{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T13:01:02Z","timestamp":1772283662588,"version":"3.50.1"},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2016,3,15]],"date-time":"2016-03-15T00:00:00Z","timestamp":1458000000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2017,4]]},"DOI":"10.1007\/s00145-016-9227-7","type":"journal-article","created":{"date-parts":[[2016,3,18]],"date-time":"2016-03-18T21:22:47Z","timestamp":1458336167000},"page":"572-600","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Jacobian Coordinates on Genus 2 Curves"],"prefix":"10.1007","volume":"30","author":[{"given":"Huseyin","family":"Hisil","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Craig","family":"Costello","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,3,15]]},"reference":[{"key":"9227_CR1","doi-asserted-by":"crossref","unstructured":"R.\u00a0M. Avanzi, A note on the signed sliding window integer recoding and a left-to-right analogue, in H.\u00a0Handschuh and M.\u00a0A. Hasan, editors, Selected Areas in Cryptography, volume 3357 of Lecture Notes in Computer Science (Springer, 2004), pp. 130\u2013143","DOI":"10.1007\/978-3-540-30564-4_9"},{"key":"9227_CR2","doi-asserted-by":"crossref","unstructured":"R.\u00a0Barbulescu, P.\u00a0Gaudry, A.\u00a0Joux, and E.\u00a0Thom\u00e9. A heuristic quasi-polynomial algorithm for discrete logarithm in finite fields of small characteristic, in P.\u00a0Q. Nguyen and E.\u00a0Oswald, editors, EUROCRYPT, volume 8441 of Lecture Notes in Computer Science (Springer, 2014), pp. 1\u201316","DOI":"10.1007\/978-3-642-55220-5_1"},{"key":"9227_CR3","doi-asserted-by":"crossref","unstructured":"D.\u00a0J. Bernstein, C.\u00a0Chuengsatiansup, T.\u00a0Lange, and P.\u00a0Schwabe. Kummer strikes back: New DH speed records., in P.\u00a0Sarkar and T.\u00a0Iwata, editors, Proceedings, Part I on Advances in Cryptology\u2014ASIACRYPT 2014\u201420th International Conference on the Theory and Application of Cryptology and Information Security, 7\u201311 December, 2014, Kaoshiung, Taiwan, R.O.C., volume 8873 of Lecture Notes in Computer Science (Springer, 2014) pp. 317\u2013337","DOI":"10.1007\/978-3-662-45611-8_17"},{"key":"9227_CR4","doi-asserted-by":"crossref","unstructured":"D.\u00a0J. Bernstein and T.\u00a0Lange. Faster addition and doubling on elliptic curves, in ASIACRYPT 2007, volume 4833 of LNCS (Springer, 2007), pp. 29\u201350","DOI":"10.1007\/978-3-540-76900-2_3"},{"key":"9227_CR5","unstructured":"D.\u00a0J. Bernstein and T.\u00a0Lange (2014). Explicit-formulas database, accessed 2 January 2014. \n                    http:\/\/www.hyperelliptic.org\/EFD\/"},{"key":"9227_CR6","unstructured":"D.\u00a0J. Bernstein and T.\u00a0Lange. eBACS: ECRYPT Benchmarking of Cryptographic Systems, accessed 28 September, 2013. \n                    http:\/\/bench.cr.yp.to"},{"key":"9227_CR7","unstructured":"G.\u00a0Bisson, R.\u00a0Cosset, and D.\u00a0Robert. AVIsogenies\u2014a library for computing isogenies between abelian varieties, November 2012. \n                    http:\/\/avisogenies.gforge.inria.fr"},{"key":"9227_CR8","doi-asserted-by":"crossref","unstructured":"J.\u00a0W. Bos, C.\u00a0Costello, H.\u00a0Hisil, and K.\u00a0Lauter. Fast cryptography in genus 2, in T.\u00a0Johansson and P.\u00a0Q. Nguyen, editors, EUROCRYPT, volume 7881 of Lecture Notes in Computer Science (Springer, 2013), pp. 194\u2013210. full version available at: \n                    http:\/\/eprint.iacr.org\/2012\/670","DOI":"10.1007\/978-3-642-38348-9_12"},{"key":"9227_CR9","doi-asserted-by":"crossref","unstructured":"W.\u00a0Bosma, J.\u00a0Cannon, and C.\u00a0Playoust. The Magma algebra system. I. The user language. J. Symb. Comput. 24(3\u20134), 235\u2013265 (1997). [Computational algebra and number theory (London, 1993)]","DOI":"10.1006\/jsco.1996.0125"},{"key":"9227_CR10","doi-asserted-by":"crossref","unstructured":"E.\u00a0Brier and M.\u00a0Joye. Weierstra\u00df elliptic curves and side-channel attacks, in Public Key Cryptography (Springer, 2002), pp. 335\u2013345","DOI":"10.1007\/3-540-45664-3_24"},{"key":"9227_CR11","doi-asserted-by":"crossref","unstructured":"D.\u00a0V. Chudnovsky and G.\u00a0V. Chudnovsky. Sequences of numbers generated by addition in formal groups and new primality and factorization tests. Adv. Appl. Math. 7(4), 385\u2013434 (1986)","DOI":"10.1016\/0196-8858(86)90023-0"},{"key":"9227_CR12","doi-asserted-by":"crossref","unstructured":"C.\u00a0Costello and K.\u00a0Lauter. Group law computations on Jacobians of hyperelliptic curves, in A.\u00a0Miri and S.\u00a0Vaudenay, editors, Selected Areas in Cryptography, volume 7118 of Lecture Notes in Computer Science (Springer, 2011), pp. 92\u2013117","DOI":"10.1007\/978-3-642-28496-0_6"},{"key":"9227_CR13","unstructured":"O.\u00a0Diao and M.\u00a0Joye. Unified addition formul\u00e6 for hyperelliptic curve cryptosystems, in 3rd Workshop on Mathematical Cryptology (WMC 2012) and 3rd International Conference on Symbolic Computation and Cryptography (SCC 2012) (2012), pp. 45\u201350"},{"key":"9227_CR14","unstructured":"S.\u00a0Erickson, T.\u00a0Ho, and S.\u00a0Zemedkun. Explicit projective formulas for real hyperelliptic curves of genus 2. Adv. Math. Commun. (2014) (To appear)"},{"key":"9227_CR15","doi-asserted-by":"crossref","unstructured":"X.\u00a0Fan and G.\u00a0Gong. Efficient explicit formulae for genus 2 hyperelliptic curves over prime fields and their implementations, in C.\u00a0Adams, A.\u00a0Miri, and M.\u00a0Wiener, editors, Selected Areas in Cryptography, volume 4876 of Lecture Notes in Computer Science (Springer, Berlin, Heidelberg, 2007), pp. 155\u2013172","DOI":"10.1007\/978-3-540-77360-3_11"},{"key":"9227_CR16","doi-asserted-by":"crossref","unstructured":"A.\u00a0Faz-Hern\u00e1ndez, P.\u00a0Longa, and A.\u00a0H. Sanchez. Efficient and secure algorithms for GLV-based scalar multiplication and their implementation on GLV-GLS curves, in J.\u00a0Benaloh, editor, CT-RSA, volume 8366 of Lecture Notes in Computer Science (Springer, 2014), pp. 1\u201327","DOI":"10.1007\/978-3-319-04852-9_1"},{"key":"9227_CR17","doi-asserted-by":"crossref","unstructured":"S.\u00a0D. Galbraith, M.\u00a0Harrison, and D.\u00a0J. Mireles Morales. Efficient hyperelliptic arithmetic using balanced representation for divisors, in A.\u00a0J. van\u00a0der Poorten and A.\u00a0Stein, editors, ANTS, volume 5011 of Lecture Notes in Computer Science (Springer, 2008), pp. 342\u2013356","DOI":"10.1007\/978-3-540-79456-1_23"},{"key":"9227_CR18","doi-asserted-by":"crossref","unstructured":"S.\u00a0D. Galbraith, J.\u00a0Pujol\u00e0s, C.\u00a0Ritzenthaler, and B.\u00a0A. Smith. Distortion maps for supersingular genus two curves. J. Math. Cryptol. 3(1), 1\u201318 (2009)","DOI":"10.1515\/JMC.2009.001"},{"key":"9227_CR19","doi-asserted-by":"crossref","unstructured":"R.\u00a0P. Gallant, R.\u00a0J. Lambert, and S.\u00a0A. Vanstone. Faster point multiplication on elliptic curves with efficient endomorphisms, in J.\u00a0Kilian, editor, CRYPTO, volume 2139 of Lecture Notes in Computer Science (Springer, 2001), pp. 190\u2013200","DOI":"10.1007\/3-540-44647-8_11"},{"key":"9227_CR20","doi-asserted-by":"crossref","unstructured":"P.\u00a0Gaudry. Fast genus 2 arithmetic based on Theta functions. J. Math. Cryptol. JMC 1(3), 243\u2013265 (2007)","DOI":"10.1515\/JMC.2007.012"},{"key":"9227_CR21","doi-asserted-by":"crossref","unstructured":"P.\u00a0Gaudry, D.\u00a0R. Kohel, and B.\u00a0A. Smith. Counting points on genus 2 curves with real multiplication, in D.\u00a0H. Lee and X.\u00a0Wang, editors, ASIACRYPT, volume 7073 of Lecture Notes in Computer Science (Springer, 2011), pp. 504\u2013519","DOI":"10.1007\/978-3-642-25385-0_27"},{"key":"9227_CR22","doi-asserted-by":"crossref","unstructured":"P.\u00a0Gaudry and E.\u00a0Schost. Genus 2 point counting over prime fields. J. Symb. Comput. 47(4), 368\u2013400 (2012)","DOI":"10.1016\/j.jsc.2011.09.003"},{"key":"9227_CR23","doi-asserted-by":"crossref","unstructured":"R.\u00a0R. Goundar, M.\u00a0Joye, A.\u00a0Miyaji, M.\u00a0Rivain, and A.\u00a0Venelli. Scalar multiplication on Weierstra\u00df elliptic curves from Co-Z arithmetic. J. Cryptogr. Eng. 1(2), 161\u2013176 (2011)","DOI":"10.1007\/s13389-011-0012-0"},{"key":"9227_CR24","unstructured":"M.\u00a0Hamburg. Fast and compact elliptic-curve cryptography. Cryptology ePrint Archive, Report 2012\/309 (2012). \n                    http:\/\/eprint.iacr.org\/"},{"key":"9227_CR25","unstructured":"H.\u00a0Hisil. Elliptic curves, group law, and efficient computation. PhD thesis, Queensland University of Technology (2010)"},{"key":"9227_CR26","doi-asserted-by":"crossref","unstructured":"N.\u00a0Koblitz. Elliptic curve cryptosystems. Math. Comput. 48(177), 203\u2013209 (1987)","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"9227_CR27","doi-asserted-by":"crossref","unstructured":"N.\u00a0Koblitz. Hyperelliptic cryptosystems. J. Cryptol. 1(3), 139\u2013150 (1989)","DOI":"10.1007\/BF02252872"},{"key":"9227_CR28","unstructured":"V.\u00a0Kovtun and S.\u00a0Kavun. Co-Z divisor addition formulae in Jacobian of genus 2 hyperelliptic curves over prime fields. Cryptology ePrint Archive, Report 2010\/498 (2010). \n                    http:\/\/eprint.iacr.org\/"},{"key":"9227_CR29","doi-asserted-by":"crossref","unstructured":"T.\u00a0Lange. Formulae for arithmetic on genus 2 hyperelliptic curves. Appl. Algebra Eng. Commun. Comput. 15(5), 295\u2013328 (2005)","DOI":"10.1007\/s00200-004-0154-8"},{"key":"9227_CR30","unstructured":"P.\u00a0Longa and A.\u00a0Miri. New composite operations and precomputation scheme for elliptic curve cryptosystems over prime fields, in R.\u00a0Cramer, editor, Public Key Cryptography PKC 2008, volume 4939 of Lecture Notes in Computer Science (Springer, Berlin, Heidelberg, 2008), pp. 189\u2013201"},{"key":"9227_CR31","unstructured":"D.\u00a0Lubicz and D.\u00a0Robert. A generalisation of Miller\u2019s algorithm and applications to pairing computations on abelian varieties. Cryptology ePrint Archive, Report 2013\/192 (2013). \n                    http:\/\/eprint.iacr.org\/"},{"key":"9227_CR32","doi-asserted-by":"crossref","unstructured":"N.\u00a0Meloni. New point addition formulae for ECC applications, in C.\u00a0Carlet and B.\u00a0Sunar, editors, WAIFI, volume 4547 of Lecture Notes in Computer Science (Springer, 2007), pp. 189\u2013201","DOI":"10.1007\/978-3-540-73074-3_15"},{"key":"9227_CR33","doi-asserted-by":"crossref","unstructured":"V.\u00a0S. Miller. Use of elliptic curves in cryptography, in H.\u00a0C. Williams, editor, CRYPTO, volume 218 of Lecture Notes in Computer Science (Springer, 1985), pp. 417\u2013426","DOI":"10.1007\/3-540-39799-X_31"},{"key":"9227_CR34","doi-asserted-by":"crossref","unstructured":"P.\u00a0L. Montgomery. Speeding the Pollard and elliptic curve methods of factorization. Math. Comput. 48(177), 243\u2013264 (1987)","DOI":"10.1090\/S0025-5718-1987-0866113-7"},{"key":"9227_CR35","unstructured":"A.-M. Spallek. Kurven vom geschlecht 2 und ihre anwendung in public-key-kryptosystemen. PhD thesis, Universit\u00e4t Essen. Institut f\u00fcr Experimentelle Mathematik (1994)"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-016-9227-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s00145-016-9227-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-016-9227-7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-016-9227-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,4,8]],"date-time":"2020-04-08T08:15:48Z","timestamp":1586333748000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s00145-016-9227-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,3,15]]},"references-count":35,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,4]]}},"alternative-id":["9227"],"URL":"https:\/\/doi.org\/10.1007\/s00145-016-9227-7","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,3,15]]},"assertion":[{"value":"2 December 2014","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 January 2016","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 March 2016","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}