Paper 2025/1751

On the Existence and Construction of Very Strong Elliptic Curves

Andrey S. Shchebetov, Skolkovo Institute of Science and Technology
Abstract

This paper introduces new, stringent security notions for elliptic curves. We define two new classes of strong elliptic curves, which offer resilience against a broader range of known attacks, including those leveraging the twist. To construct curves satisfying these exceptional criteria, we developed a highly scalable, parallel framework based on the complex multiplication method. Our approach efficiently navigates the vast parameter space defined by safe primes and fundamental discriminants. The core of our method is the efficient scanning algorithm that postpones expensive curve construction until after orders are confirmed to meet our security definitions, enabling significant search efficiency. As a concrete demonstration of our definitions and techniques, we conducted a large-scale computational experiment. This resulted in the first known construction of $91$ very strong 256-bit curves with extreme twist orders (i.e., where the curve order is a safe prime and the twist order is prime) and cofactors $u=1$ along with $4$ such 512-bit curves meeting the extreme twist order criteria. Among these, one 512-bit curve has both its order (a safe prime) and its twist order being prime, while the other three have a small cofactor ($u=7$) but their twist orders are primes. All curves are defined over finite fields whose orders are safe primes. These results not only prove the existence of these cryptographically superior curves but also provide a viable path for their systematic generation, shifting the paradigm from constructing curves faster to constructing curves that are fundamentally stronger.

Metadata
Available format(s)
PDF
Category
Public-key cryptography
Publication info
Preprint.
Keywords
elliptic curve cryptographycomplex multiplicationcryptographic standardshigh-performance computing
Contact author(s)
andrey shchebetov @ skoltech ru
History
2025-10-01: revised
2025-09-24: received
See all versions
Short URL
https://ia.cr/2025/1751
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1751,
      author = {Andrey S. Shchebetov},
      title = {On the Existence and Construction of Very Strong Elliptic Curves},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1751},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1751}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.