Faster Halvings in Genus 2
We study divisor class halving for hyperelliptic curves of genus 2 over binary fields. We present explicit halving formulas for the most interesting curves (from a cryptographic perspective), as well as all other curves whose group order is not divisible by 4. Each type of curve is characterized by the degree and factorization form of the polynomial h(x) in the curve equation. For each of these curves, we provide explicit halving formulæ for all possible divisor classes, and not only the most frequent case where the degree of the first polynomial in the Mumford representation is 2. In the optimal performance case, where h(x) = x, we also improve on the state-of-the-art and when h(x) is irreducible of degree 2, we achieve significant savings over both the doubling as well as the previously fastest halving formulas.
Keywordshyperelliptic curve genus 2 halving binary field
- 2.Avanzi, R.M.: A Note on Square Roots in Binary Fields (preprint)Google Scholar
- 5.Gaudry, P.: Index calculus for abelian varieties and the elliptic curve discrete logarithm problem (2004) (preprint), http://eprint.iacr.org/2004/073/
- 7.Kitamura, I., Katagi, M., Takagi, T.: A Complete Divisor Class Halving Algorithm for Hyperelliptic Curve Cryptosystems of Genus Two (preprint) (2005), http://eprint.iacr.org/2005/255/
- 14.Schroeppel, R.: Elliptic curves: Twice as fast! In: Crypto 2000 Rump Session (2000)Google Scholar
- 15.Thériault, N.: Weil Descent for Artin-Schreier Curves (preprint) (2003), http://homepage.mac.com/ntheriau