Search arXivSearch

arXiv · 1110.0966

Optimality of the Width-$w$ Non-adjacent Form: General Characterisation and the Case of Imaginary Quadratic Bases

Abstract

Efficient scalar multiplication in Abelian groups (which is an important operation in public key cryptography) can be performed using digital expansions. Apart from rational integer bases (double-and-add algorithm), imaginary quadratic integer bases are of interest for elliptic curve cryptography, because the Frobenius endomorphism fulfils a quadratic equation. One strategy for improving the efficiency is to increase the digit set (at the prize of additional precomputations). A common choice is the width\nbd-$w$ non-adjacent form (\wNAF): each block of $w$ consecutive digits contains at most one non-zero digit. Heuristically, this ensures a low weight, i.e.\ number of non-zero digits, which translates in few costly curve operations. This paper investigates the following question: Is the \wNAF{}-expansion optimal, where optimality means minimising the weight over all possible expansions with the same digit set? The main characterisation of optimality of \wNAF{}s can be formulated in the following more general setting: We consider an Abelian group together with an endomorphism (e.g., multiplication by a base element in a ring) and a finite digit set. We show that each group element has an optimal \wNAF{}-expansion if and only if this is the case for each sum of two expansions of weight 1. This leads both to an algorithmic criterion and to generic answers for various cases. Imaginary quadratic integers of trace at least 3 (in absolute value) have optimal \wNAF{}s for $w\ge 4$. The same holds for the special case of base $(\pm 3\pm\sqrt{-3})/2$ and $w\ge 2$, which corresponds to Koblitz curves in characteristic three. In the case of $τ=\pm1\pm i$, optimality depends on the parity of $w$. Computational results for small trace are given.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Clemens Heuberger, Daniel Krenn. 2011-10-05. Optimality of the Width-$w$ Non-adjacent Form: General Characterisation and the Case of Imaginary Quadratic Bases. https://doi.org/10.5802/jtnb.840

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

On the Pair Correlation of Zeros of $L$-Functions for Non-CM Newforms in Shifted Ranges

We study the pair correlation between zeros of a shifted auxiliary $ L $-function attached to a non-CM newform, the scale of which is a fixed constant. We prove an unconditional asymptotic result for the pair correlation and introduce a simplicity hypothesis for the zeros of this function, which if true means that multiple zeros of the original $ L $-function cannot be separated by the same fixed distance. Our results provide macroscopic information in contrast to the pair correlation of the original $ L $-function which is of microscopic nature.

math.NT

Prime Solutions to a Binary Additive Equation and Mixed Moments of Character Sums

We obtain an asymptotic formula with a power-saving error term for counting the integer points $(a,b,c,d)$ in an expanding box that satisfy the determinant equation $x_1x_2-x_3x_4 =r$ for $r \neq 0 $ with two of entries to be prime. Finally, these estimates are applied to evaluate mixed fourth moments of Dirichlet character sums over integers and primes, yielding non-trivial bounds. The method involves the Poisson summation formula and the estimation for the average of the sums of the Kloosterman fractions over primes.

math.NT

On properness of moduli stacks of $D^{\times}$-shtukas over ramified legs

Given a maximal order $\mathcal{D}$ of a central division algebra $D$ over a global function field $F$, we prove an explicit sufficient condition for moduli stacks of $\mathcal{D}^\times$-shtukas to be proper over a finite field (modulo a suitable central action) in terms of the \emph{local invariants} of $D$ and \emph{bounds}. Our proof is a refinement of E.~Lau's result (Duke Math. J. \textbf{140} (2007)), which showed the properness of the \emph{leg morphism} (or \emph{characteristic morphism}) away from the ramification locus of $D$. %, by carefully measuring the contribution of ``ramified legs''. We also establish non-emptiness of Newton and Kottwitz--Rapoport strata for moduli stacks of $\mathcal{B}^\times$-shtukas, where $\mathcal{B}$ is a maximal order of a central simple algebra over $F$.

math.NT