cronokirby

(2026-04) Fast Isogeny Evaluation on Binary Curves

2026-04-10

Abstract

We give efficient formulas to evaluate isogenies of ordinary elliptic curves over finite fields of characteristic 22, extending the odd-characteristic techniques of Hisil--Costello and Renes to binary fields. For odd prime degree =2s+1\ell = 2s+1, our affine product evaluation computes the image xx-coordinate using 5sM5s\mathbf{M} field multiplications, or 4sM4s\mathbf{M} when the kernel points are normalized. We derive an inversion-free variant that evaluates the xx-map in projective and twisted Kummer coordinates, allowing carried points to remain projective across successive isogeny steps. Over F2511\mathbb{F}_{2^{511}}, microbenchmarks show that the inversion-free projective and twisted variants are faster than Vélu-style xx-evaluation when outputs are kept in projective/twisted form, while the affine one-inversion variant is about 4.2×4.2\times faster.