2012
DOI: 10.1090/s0025-5718-2012-02633-0
|View full text |Cite
|
Sign up to set email alerts
|

ECM using Edwards curves

Abstract: Abstract. This paper introduces GMP-EECM, a fast implementation of the elliptic-curve method of factoring integers. GMP-EECM is based on, but faster than, the well-known GMP-ECM software. The main changes are as follows: (1) use Edwards curves instead of Montgomery curves; (2) use twisted inverted Edwards coordinates; (3) use signedsliding-window addition chains; (4) batch primes to increase the window size; (5) choose curves with small parameters a, d, X1, Y1, Z1; (6) choose curves with larger torsion.

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

1
44
0

Year Published

2017
2017
2021
2021

Publication Types

Select...
5
1

Relationship

0
6

Authors

Journals

citations
Cited by 33 publications
(45 citation statements)
references
References 34 publications
1
44
0
Order By: Relevance
“…The two most profitable possibilities, Z/12Z and Z/2Z × Z/8Z, are characterized for families of Edwards curves in [5,Section 6]. On the other hand, the fastest scalar multiplication is obtained in [7] for a = −1 twisted Edward curves; as shown in [5], however, this limits the possibilities for interesting torsion groups (i.e., with cardinality greater than four) to Z/6Z, Z/8Z or Z/2Z × Z/4Z, thereby in particular excluding the two most profitable ones.…”
Section: Edwards Curves and Elliptic Curve Methodsmentioning
confidence: 99%
See 4 more Smart Citations
“…The two most profitable possibilities, Z/12Z and Z/2Z × Z/8Z, are characterized for families of Edwards curves in [5,Section 6]. On the other hand, the fastest scalar multiplication is obtained in [7] for a = −1 twisted Edward curves; as shown in [5], however, this limits the possibilities for interesting torsion groups (i.e., with cardinality greater than four) to Z/6Z, Z/8Z or Z/2Z × Z/4Z, thereby in particular excluding the two most profitable ones.…”
Section: Edwards Curves and Elliptic Curve Methodsmentioning
confidence: 99%
“…On the other hand, the fastest scalar multiplication is obtained in [7] for a = −1 twisted Edward curves; as shown in [5], however, this limits the possibilities for interesting torsion groups (i.e., with cardinality greater than four) to Z/6Z, Z/8Z or Z/2Z × Z/4Z, thereby in particular excluding the two most profitable ones. For ECM the issue was settled in [4] where a = −1 twisted Edwards curves were compared to curves with E tors isomorphic to Z/12Z and Z/2Z × Z/8Z: it was found that the disadvantage of the formers' smaller torsion groups is outweighed by their faster scalar multiplication.…”
Section: Edwards Curves and Elliptic Curve Methodsmentioning
confidence: 99%
See 3 more Smart Citations