Source author record

David Kohel

David Kohel appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

7works
2topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

7 published item(s)

preprint2016arXiv

Arithmetic of split Kummer surfaces: Montgomery endomorphism of Edwards products

Let $E$ be an elliptic curve, $\mathcal{K}_1$ its Kummer curve $E/\{\pm1\}$, $E^2$ its square product, and $\mathcal{K}_2$ the split Kummer surface $E^2/\{\pm1\}$. The addition law on $E^2$ gives a large endomorphism ring, which induce endomorphisms of $\mathcal{K}_2$. With a view to the practical applications to scalar multiplication on $\mathcal{K}_1$, we study the explicit arithmetic of $\mathcal{K}_2$.

preprint2016arXiv

Efficient arithmetic on elliptic curves in characteristic 2

We present normal forms for elliptic curves over a field of characteristic $2$ analogous to Edwards normal form, and determine bases of addition laws, which provide strikingly simple expressions for the group law. We deduce efficient algorithms for point addition and scalar multiplication on these forms. The resulting algorithms apply to any elliptic curve over a field of characteristic $2$ with a $4$-torsion point, via an isomorphism with one of the normal forms. We deduce algorithms for duplication in time $2M + 5S + 2m_c$ and for addition of points in time $7M + 2S$, where $M$ is the cost of multiplication, $S$ the cost of squaring, and $m_c$ the cost of multiplication by a constant. By a study of the Kummer curves $\mathcal{K} = E/\{[\pm1]\}$, we develop an algorithm for scalar multiplication with point recovery which computes the multiple of a point $P$ with $4M + 4S + 2m_c + m_t$ per bit where $m_t$ is multiplication by a constant that depends on $P$.

preprint2016arXiv

The geometry of efficient arithmetic on elliptic curves

The arithmetic of elliptic curves, namely polynomial addition and scalar multiplication, can be described in terms of global sections of line bundles on $E\times E$ and $E$, respectively, with respect to a given projective embedding of $E$ in $\mathbb{P}^r$. By means of a study of the finite dimensional vector spaces of global sections, we reduce the problem of constructing and finding efficiently computable polynomial maps defining the addition morphism or isogenies to linear algebra. We demonstrate the effectiveness of the method by improving the best known complexity for doubling and tripling, by considering families of elliptic curves admiting a $2$-torsion or $3$-torsion point.

preprint2014arXiv

On the quaternion $\ell$-isogeny path problem

Let $\cO$ be a maximal order in a definite quaternion algebra over $\mathbb{Q}$ of prime discriminant $p$, and $\ell$ a small prime. We describe a probabilistic algorithm, which for a given left $O$-ideal, computes a representative in its left ideal class of $\ell$-power norm. In practice the algorithm is efficient, and subject to heuristics on expected distributions of primes, runs in expected polynomial time. This breaks the underlying problem for a quaternion analog of the Charles-Goren-Lauter hash function, and has security implications for the original CGL construction in terms of supersingular elliptic curves.

preprint2012arXiv

Complete addition laws on abelian varieties

We prove that under any projective embedding of an abelian variety A of dimension g, a complete system of addition laws has cardinality at least g+1, generalizing of a result of Bosma and Lenstra for the Weierstrass model of an elliptic curve in P^2. In contrast with this geometric constraint, we moreover prove that if k is any field with infinite absolute Galois group, then there exists, for every abelian variety A/k, a projective embedding and an addition law defined for every pair of k-rational points. For an abelian variety of dimension 1 or 2, we show that this embedding can be the classical Weierstrass model or embedding in P^15, respectively, up to a finite number of counterexamples for |k| less or equal to 5.

preprint2011arXiv

Addition law structure of elliptic curves

The study of alternative models for elliptic curves has found recent interest from cryptographic applications, once it was recognized that such models provide more efficiently computable algorithms for the group law than the standard Weierstrass model. Examples of such models arise via symmetries induced by a rational torsion structure. We analyze the module structure of the space of sections of the addition morphisms, determine explicit dimension formulas for the spaces of sections and their eigenspaces under the action of torsion groups, and apply this to specific models of elliptic curves with parametrized torsion subgroups.

preprint2011arXiv

Counting Points on Genus 2 Curves with Real Multiplication

We present an accelerated Schoof-type point-counting algorithm for curves of genus 2 equipped with an efficiently computable real multiplication endomorphism. Our new algorithm reduces the complexity of genus 2 point counting over a finite field (\F_{q}) of large characteristic from (\widetilde{O}(\log^8 q)) to (\widetilde{O}(\log^5 q)). Using our algorithm we compute a 256-bit prime-order Jacobian, suitable for cryptographic applications, and also the order of a 1024-bit Jacobian.