2021INFORMATION TECHNOLOGY AND SOCIETYOpen access

APPROACH TO CHECKING THE SUPERSINGULARITY OF ELLIPTIC CURVES AND CALCULATING THEIR ORDER

Ruslan SKURATOVSKYI

Open full text 0 citations

Abstract

Most cryptosystems in modern cryptography can naturally be “translated” into elliptical curves. We consideralgebraic Edwards curves over a finite field, which are currently one of the most promising carriers of sets of points used forfast group operations [1; 2; 14], which are available in asymmetric cryptosystems, in particular for the construction of randomcryptocurrency sequences.It is shown that the projective curve Ea d, is not elliptical. The aim of this work is to find a criterion and sufficient conditionsfor the supersingularity of the Edwards curve p and an elliptic curve in the form of Montgomery over a simple field andthen generalize this criterion for a finite algebraic extension of this field to Fpn . The obtained result allows us to construct allsupersingular curves of Edwards and Montgomery without factorizing the polynomial from which the curve is present in therecord.In [10], the proof of the supersingularity of a curve Ed was presented only for the coefficients d 2, d 2 1 over p , andour goal is to study all the coefficients at which this curve is supersingular. In our work we found the criteria and sufficientconditions for the supersingularity of the Edwards curve and the elliptic curve in the form of Montgomery over the field Fpn , ie we investigated at what coefficients a pair of curves with a Frobenius trace equal to 0. The Montgomery curves over the fieldof characteristic 2 have zero j-invariant. Not only a specific set of coefficients with the corresponding characteristics of thefields at which these curves are supersingular is found, but also a general formula by which it is possible to determine whetherthe curve is supersingular over a given field or not. The paper summarizes the result on the supersingularity of the curve overp obtained in [10] for the coefficients d 2, d 2 1 in the case of arbitrary expansion of a simple field pn and clarifies theformulation of Theorem 3 from [10]. A similar study was performed for elliptic curves in the form of Montgomery.

Open-access reader

About this research paper

What this paper is about

Most cryptosystems in modern cryptography can naturally be “translated” into elliptical curves. We consideralgebraic Edwards curves over a finite field, which are currently one of the most promising carriers of sets of points used forfast group operations [1; 2; 14], which are available in asymmetric cryptosystems, in particular for the construction of randomcryptocurrency sequences.It is shown that the projective curve Ea d, is not elliptical. The aim of this work is to find a criterion and sufficient conditionsfor the supersingularity of the Edwards curve p and an elliptic curve in the form of Montgomery over a simple field andthen generalize this criterion for a finite algebraic extension of this field to Fpn . The obtained result allows us to construct allsupersingular curves of Edwards and Montgomery without factorizing the polynomial from which the curve is present in therecord.In [10], the proof of the supersingularity of a curve Ed was presented only for the coefficients d 2, d 2 1 over p , andour goal is to study all the coefficients at which this curve is supersingular. In our work we found the criteria and sufficientconditions for the supersingularity of the Edwards curve and the elliptic curve in the form of Montgomery over the field Fpn , ie we investigated at what coefficients a pair of curves with a Frobenius trace equal to 0. The Montgomery curves over the fieldof characteristic 2 have zero j-invariant. Not only a specific set of coefficients with the corresponding characteristics of thefields at which these curves are supersingular is found, but also a general formula by which it is possible to determine whetherthe curve is supersingular over a given field or not. The paper summarizes the result on the supersingularity of the curve overp obtained in [10] for the coefficients d 2, d 2 1 in the case of arbitrary expansion of a simple field pn and clarifies theformulation of Theorem 3 from [10]. A similar study was performed for elliptic curves in the form of Montgomery.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Most cryptosystems in modern cryptography can naturally be “translated” into elliptical curves. We consideralgebraic Edwards curves over a finite field, which are currently one of the most promising carriers of sets of points used forfast group operations [1; 2; 14], which are available in asymmetric cryptosystems, in particular for the construction of randomcryptocurrency sequences.It is shown that the projective curve Ea d, is not elliptical. The aim of this work is to find a criterion and sufficient conditionsfor the supersingularity of the Edwards curve p and an elliptic curve in the form of Montgomery over a simple field andthen generalize this criterion for a finite algebraic extension of this field to Fpn . The obtained result allows us to construct allsupersingular curves of Edwards and Montgomery without factorizing the polynomial from which the curve is present in therecord.In [10], the proof of the supersingularity of a curve Ed was presented only for the coefficients d 2, d 2 1 over p , andour goal is to study all the coefficients at which this curve is supersingular. In our work we found the criteria and sufficientconditions for the supersingularity of the Edwards curve and the elliptic curve in the form of Montgomery over the field Fpn , ie we investigated at what coefficients a pair of curves with a Frobenius trace equal to 0. The Montgomery curves over the fieldof characteristic 2 have zero j-invariant. Not only a specific set of coefficients with the corresponding characteristics of thefields at which these curves are supersingular is found, but also a general formula by which it is possible to determine whetherthe curve is supersingular over a given field or not. The paper summarizes the result on the supersingularity of the curve overp obtained in [10] for the coefficients d 2, d 2 1 in the case of arbitrary expansion of a simple field pn and clarifies theformulation of Theorem 3 from [10]. A similar study was performed for elliptic curves in the form of Montgomery.

Key concepts: Hessian form of an elliptic curve, Supersingular elliptic curve, Elliptic curve, Schoof's algorithm, Mathematics, Tripling-oriented Doche–Icart–Kohel curve, Jacobian curve, Edwards curve

Related papers

Back to paper searchBrowse research topicsOriginal source
APPROACH TO CHECKING THE SUPERSINGULARITY OF ELLIPTIC CURVES AND CALCULATING THEIR ORDER — Research Paper | ScholarLens