摘要 |
A system and method for achieving secure and fast computation in hyperelliptic cryptography is realized. Fast scalar multiplication is achieve by executing computing operations including halving as computing processing in scalar multiplication with respect to a divisor D in hyperelliptic curve cryptography. For example, computing operations including halving are executed in scalar multiplication with respect to a divisor D on a hyperelliptic curve of genus 2 in characteristic 2 having h(x)=x 2 +x+h 0 , f 4 =0 as parameters, a hyperelliptic curve of genus 2 in characteristic 2 having h(x)=x 2 +h 1 x+h 0 , f 4 =0 as parameters, or a hyperelliptic curve of genus 2 in characteristic 2 having h(x)=x as a parameter. Further, reduced complexity and faster computation are realized through the application of a table that records which of k 1 , k 1 ', (k 0 , k 0 ') is correct on the basis of a computed value of [1/2 i D] with respect to a fixed divisor D, and through a reduction in the number of inversion operations. |