论文标题

超高的爱德华兹曲线的3和5个发育

3- and 5-Isogenies of Supersingular Edwards Curves

论文作者

Bessalov, Anatoly, Grubiyan, Evgeniy, Sokolov, Volodymyr, Skladannyi, Pavlo

论文摘要

分析了完整和二次超级爱德华兹曲线的3个和5个发病型的特性和条件。为了基于SIDH算法的键封装,提议使用最小奇数3和5的等值异常,这允许绕过第二和第四阶的奇异点的问题,这是2个发育界的特征。对简单字段的完整,二次和扭曲的Edwards曲线的类别的主要属性进行了回顾。奇数程度的等级方程将减少为以Weierstrass形式适应曲线的形式。为此,请使用以广义爱德华兹形式添加曲线点的修改定律,该定律保留了曲线返回点的水平对称性。给出了在小简单字段上完整的爱德华兹超级曲线的3和5异基的计算的示例,并讨论了ISEGEN组成的特性,用于用大阶核计算。对于射影坐标中的完整和二次爱德华兹曲线类别中的奇数3和5计算的计算,获得了方程。构建算法是用于计算复杂性6M + 4s和12m + 5s的Edwards曲线的3和5异基因。发现了存在4x3mx5n和8x3mx5n的超强完整和二次爱德华兹的曲线的条件。在以128位的量子安全级别实现SIDH算法时,确定了加密系统的某些参数。

An analysis is made of the properties and conditions for the existence of 3- and 5-isogenies of complete and quadratic supersingular Edwards curves. For the encapsulation of keys based on the SIDH algorithm, it is proposed to use isogeny of minimal odd degrees 3 and 5, which allows bypassing the problem of singular points of the 2nd and 4th orders, characteristic of 2-isogenies. A review of the main properties of the classes of complete, quadratic, and twisted Edwards curves over a simple field is given. Equations for the isogeny of odd degrees are reduced to a form adapted to curves in the form of Weierstrass. To do this, use the modified law of addition of curve points in the generalized Edwards form, which preserves the horizontal symmetry of the curve return points. Examples of the calculation of 3- and 5-isogenies of complete Edwards supersingular curves over small simple fields are given, and the properties of the isogeny composition for their calculation with large-order kernels are discussed. Equations are obtained for upper complexity estimates for computing isogeny of odd degrees 3 and 5 in the classes of complete and quadratic Edwards curves in projective coordinates; algorithms are constructed for calculating 3- and 5-isogenies of Edwards curves with complexity 6M + 4S and 12M + 5S, respectively. The conditions for the existence of supersingular complete and quadratic Edwards curves of order 4x3mx5n and 8x3mx5n are found. Some parameters of the cryptosystem are determined when implementing the SIDH algorithm at the level of quantum security of 128 bits.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源