[Resource Topic] 2022/1164: Point-Halving and Subgroup Membership in Twisted Edwards Curves

Welcome to the resource topic for 2022/1164

Title:
Point-Halving and Subgroup Membership in Twisted Edwards Curves

Authors: Thomas Pornin

Abstract:

In this short note, we describe a process for halving a point on a
twisted Edwards curve. This can be used to test whether a given point
is in the subgroup of prime order \ell, which is used by some
cryptographic protocols. On Curve25519, this new test is about twice
faster than the classic method consisting of multiplying the source
point by \ell.

ePrint: https://eprint.iacr.org/2022/1164

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .