Paper 2026/1299
Decomposition of compressions on elliptic curves and point recovery
Abstract
Let $E$ be an elliptic curve over a perfect field $K$. A function $f\in K(E)$ is a compression of degree 2 on $E$ if $f(-P) = f(P)$ for all $P\in E$, and the field extension $K(f)\subset K(E)$ is of degree 2. For a finite subgroup $G\subset E$ over $K$ a function $w\in K(E)$ we will call a $G$-compression if $w(\pm P +G) = w(P)$ for all $P\in E$, and the field extension $K(w)\subset K(E)$ is of degree $2|G|$. We will show that $w\in K(E)$ is a $G$-compression if and only if $w = f\circ \Phi$ for a separable isogeny $\Phi:E\to E'$ over $K$ with $\ker \Phi=G$, an elliptic curve $E'/K$, and a compression $f\in K(E')$ of degree 2 on $E'$. This allows to obtain a doubling, a differential addition, and a method for point recovery for $G$-compressions using known properties of compressions of degree 2. For $G$-compressions $w$ studied in the literature on an extended Jacobi quartic, a twisted Edwards curve, a twisted Jacobi intersection, and a twisted Hessian curve (for the first and third model additional conditions on coefficients are assumed) we will give the decomposition $w = f\circ \Phi$ as above, and the function induced by the dual isogeny $\widehat{\Phi}$ and compressions of degree 2, which can be used for point recovery. For the first three models this isogeny $\Phi$ is to a Montgomery curve over $K$, and has the first coordinate $x(\Phi)=1/w$. We also give isomorphisms from some models of elliptic curves to a Montgomery curve.
Metadata
- Available format(s)
-
PDF
- Category
- Public-key cryptography
- Publication info
- Preprint.
- Keywords
- elliptic curve cryptographyalternative models of elliptic curvescompressionMontgomery ladder algorithmisogeny
- Contact author(s)
- rdrylo @ sgh waw pl
- History
- 2026-06-24: approved
- 2026-06-22: received
- See all versions
- Short URL
- https://ia.cr/2026/1299
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1299,
author = {Robert Dryło},
title = {Decomposition of compressions on elliptic curves and point recovery},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1299},
year = {2026},
url = {https://eprint.iacr.org/2026/1299}
}