[Cryptography] Existence of point of order 4 in a Montgomery curve and its quadratic twist

Ondrej Mikle ondrej.mikle at gmail.com
Tue Feb 13 09:25:03 EST 2018


On 02/13/2018 12:38 AM, Ondrej Mikle wrote:
> I was reading the original paper on Twisted Edwards Curves
> (https://eprint.iacr.org/2008/013.pdf) and there is one thing that does not seem
> right to me or I don't understand it.
> 
> Theorem 3.5 states in the proof, that exactly one of Montgomery curve or its
> nontrivial quadratic twist over field k with #k=1 mod 4 contains a point of
> order 4 and the other doesn't.
> 
> However in the proof, it mentions that both the curve and its twist have
> subgroup that is isomorphic to Z/2Z x Z/2Z.

OK, nevermind, I see now that Z/2Z x Z/2Z doesn't have a point of order 4.


Regards,
  O. Mikle


More information about the cryptography mailing list