| T. Lange, Trace-Zero Subvariety for Cryptosystems. Preprint. |
....We note that mixed coordinate systems also exist for hyperelliptic curves of genus 2 [22] 5. 2 Trace zero varieties Trace zero varieties are abelian varieties constructed essentially by Weil Descent from other varieties, such as elliptic curves [25, 14] or Jacobians of hyperelliptic curves [20, 21]. Construction and security parameters. We start with an elliptic curve (resp. hyperelliptic curve of genus g) defined over a prime field F p where p (resp. p ) has the order of magnitude of the desired group size. We also assume that the characteristic polynomial of the Frobenius ....
....prime order in which we actually implement the cryptographic primitives. As usual we want to choose it so that it has a cofactor in G as small as possible, i.e. p . It has been noted that for g(d 1) 4 the best attacks known to work on trace zero varieties have complexity O( G 0 ) [25, 21]. In what follows we consider only the case where d = 3 for simplicity. As we require the same level of security offered by, say, elliptic curves over fields of 160 bits, we have 2 also for trace zero varieties and the field F p must satisfy p 2 . Performance advantages in ....
[Article contains additional citation context not shown here]
T. Lange, Trace-Zero Subvariety for Cryptosystems. Preprint.
Online articles have much greater impact More about CiteSeer.IST Add search form to your site Submit documents Feedback
CiteSeer.IST - Copyright Penn State and NEC