Montgomery curves and their arithmetic: The case of large characteristic fields

Journal of Cryptographic Engineering | , Vol 8: pp. 227-240

Publication

Three decades ago, Montgomery introduced a new elliptic curve model for use in Lenstra’s ECM factorization algorithm. Since then, his curves and the algorithms associated with them have become foundational in the implementation of elliptic curve cryptosystems. This article surveys the theory and cryptographic applications of Montgomery curves over non-binary finite fields, including Montgomery’s x-only arithmetic and Ladder algorithm, x-only Diffie–Hellman, y-coordinate recovery, and two-dimensional and Euclidean differential addition chains such as Montgomery’s PRAC algorithm.