[Resource Topic] 2022/794: Generation of "independent" points on elliptic curves by means of Mordell--Weil lattices

Welcome to the resource topic for 2022/794

Generation of “independent” points on elliptic curves by means of Mordell–Weil lattices

Authors: Dmitrii Koshelev


This article develops a novel method of generating “independent” points on an ordinary elliptic curve E over a finite field. Such points are actively used in the Pedersen vector commitment scheme and its modifications. In particular, the new approach is relevant for Pasta curves (of j-invariant 0), which are very popular in the given type of elliptic cryptography. These curves are defined over highly 2-adic fields, hence successive generation of points via a hash function to E is an expensive solution. Our method also satisfies the NUMS (Nothing Up My Sleeve) principle, but it works faster on average. More precisely, instead of finding each point separately in constant time, we suggest to sample several points at once with some probability.

ePrint: https://eprint.iacr.org/2022/794

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .