Communications in Cryptology IACR CiC
Search requires all terms to appear in the result
Search results for Montgomery ladder
  1. Damien Robert, Nicolas Sarkis
    Published 2024-04-09 PDFPDF

    We use theta groups to study $2$-isogenies between Kummer lines, with a particular focus on the Montgomery model. This allows us to recover known formulas, along with more efficient forms for translated isogenies, which require only $2S+2m_0$ for evaluation. We leverage these translated isogenies to build a hybrid ladder for scalar multiplication on Montgomery curves with rational $2$-torsion, which cost $3M+6S+2m_0$ per bit, compared to $5M+4S+1m_0$ for the standard Montgomery ladder.