3532 articles – 5253 Notices  [english version]

inria-00103435, version 1

The 2-adic CM method for genus 2 curves with application to cryptography

Pierrick Gaudry () 1, Thomas Houtmann 2, Annegret Weng 2, Christophe Ritzenthaler 3, David Kohel 4

Asiacrypt 2006 4284 (2006) 114-129

Résumé : The complex multiplication (CM) method for genus 2 is currently the most efficient way of generating genus 2 hyperelliptic curves defined over large prime fields and suitable for cryptography. Since low class number might be seen as a potential threat, it is of interest to push the method as far as possible. We have thus designed a new algorithm for the construction of CM invariants of genus 2 curves, using 2-adic lifting of an input curve over a small finite field. This provides a numerically stable alternative to the complex analytic method in the first phase of the CM method for genus 2. As an example we compute an irreducible factor of the Igusa class polynomial system for the quartic CM field Q(i sqrt(75 + 12 sqrt(17))), whose class number is 50. We also introduce a new representation to describe the CM curves: a set of polynomials in (j1, j2, j3) which vanish on the precise set of triples which are the Igusa invariants of curves whose Jacobians have CM by a prescribed field. The new representation provides a speedup in the second phase, which uses Mestre's algorithm to construct a genus 2 Jacobian of prime order over a large prime field for use in cryptography.

  • 1 :  SPACES (INRIA Lorraine - LORIA)
  • INRIA – CNRS : UMR7503 – Université Henri Poincaré - Nancy I – Université Nancy II – Institut National Polytechnique de Lorraine (INPL)
  • 2 :  TANC (INRIA Futurs)
  • CNRS : UMR7161 – INRIA – Polytechnique - X
  • 3 :  Institut de Mathématiques de Luminy (IML)
  • CNRS : UPR9016
  • 4 :  School of Mathematics and statistics [Sydney]
  • The University of Sydney
  • Domaine : Informatique/Cryptographie et sécurité
 
  • inria-00103435, version 1
  • oai:hal.inria.fr:inria-00103435
  • Contributeur : 
  • Soumis le : Mercredi 4 Octobre 2006, 13:44:40
  • Dernière modification le : Mercredi 4 Octobre 2006, 14:40:14