{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:02:12Z","timestamp":1784390532529,"version":"3.55.0"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,4,12]],"date-time":"2021-04-12T00:00:00Z","timestamp":1618185600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,4,12]],"date-time":"2021-04-12T00:00:00Z","timestamp":1618185600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptogr Eng"],"published-print":{"date-parts":[[2022,4]]},"DOI":"10.1007\/s13389-021-00261-y","type":"journal-article","created":{"date-parts":[[2021,4,12]],"date-time":"2021-04-12T16:03:33Z","timestamp":1618243413000},"page":"107-121","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Security and efficiency trade-offs for elliptic curve Diffie\u2013Hellman at the 128-bit and 224-bit security levels"],"prefix":"10.1007","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8159-4589","authenticated-orcid":false,"given":"Kaushik","family":"Nath","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Palash","family":"Sarkar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,4,12]]},"reference":[{"key":"261_CR1","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Chuengsatiansup, C., Lange, T., Schwabe, P.: Kummer strikes back: New DH speed records. In Advances in Cryptology\u2014ASIACRYPT, volume 8873 of Lecture Notes in Computer Science, pp. 317\u2013337. Springer, (2014)","DOI":"10.1007\/978-3-662-45611-8_17"},{"key":"261_CR2","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Lange, T.: Faster addition and doubling on elliptic curves. In Advances in Cryptology\u2014ASIACRYPT, volume 4833 of Lecture Notes in Computer Science, pp. 29\u201350. Springer, (2007)","DOI":"10.1007\/978-3-540-76900-2_3"},{"key":"261_CR3","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J.: Curve25519: New Diffie-Hellman Speed Records. In Moti Yung, Yevgeniy Dodis, Aggelos Kiayias, and Tal Malkin, editors, Public Key Cryptography - PKC 2006, 9th International Conference on Theory and Practice of Public-Key Cryptography, New York, NY, USA, April 24-26, 2006, Proceedings, volume 3958 of Lecture Notes in Computer Science, pp. 207\u2013228. Springer, (2006)","DOI":"10.1007\/11745853_14"},{"key":"261_CR4","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Birkner, P., Joye, M., Lange, T., Peters, C.: Twisted Edwards curves. In Serge Vaudenay, editor, Progress in Cryptology\u2014AFRICACRYPT 2008, First International Conference on Cryptology in Africa, Casablanca, Morocco, June 11\u201314, 2008. Proceedings, volume 5023 of Lecture Notes in Computer Science, pp. 389\u2013405. Springer, (2008)","DOI":"10.1007\/978-3-540-68164-9_26"},{"key":"261_CR5","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., Yang, B.-Y.: High-speed high-security signatures. In Bart Preneel and Tsuyoshi Takagi, editors, Cryptographic Hardware and Embedded Systems\u2014CHES 2011\u201413th International Workshop, Nara, Japan, September 28 - October 1, 2011. Proceedings, volume 6917 of Lecture Notes in Computer Science, pp. 124\u2013142. Springer, (2011)","DOI":"10.1007\/978-3-642-23951-9_9"},{"issue":"2","key":"261_CR6","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s13389-012-0027-1","volume":"2","author":"DJ Bernstein","year":"2012","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., Yang, B.-Y.: High-speed high-security signatures. J. Cryptogr. Eng. 2(2), 77\u201389 (2012)","journal-title":"J. Cryptogr. Eng."},{"key":"261_CR7","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Hamburg, M., Krasnova, A., Lange, T.: Elligator: elliptic-curve points indistinguishable from uniform random strings. In Ahmad-Reza Sadeghi, Virgil\u00a0D. Gligor, and Moti Yung, editors, 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS\u201913, Berlin, Germany, November 4\u20138, 2013, pp. 967\u2013980. ACM, (2013)","DOI":"10.1145\/2508859.2516734"},{"key":"261_CR8","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Lange, T.: Montgomery curves and the Montgomery ladder. In Joppe\u00a0W. Bos and Arjen\u00a0K. Lenstra, editors, Topics in Computational Number Theory inspired by Peter L. Montgomery, pp. 82\u2013115. Cambridge University Press, (2017)","DOI":"10.1017\/9781316271575.005"},{"key":"261_CR9","doi-asserted-by":"crossref","unstructured":"Bos, J.W., Costello, C., Hisil, H., Lauter, K.E.: Fast cryptography in genus 2. In Advances in Cryptology\u2014EUROCRYPT 2013, 32nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Athens, Greece, May 26-30, 2013. Proceedings, volume 7881 of Lecture Notes in Computer Science, pp. 194\u2013210. Springer, (2013)","DOI":"10.1007\/978-3-642-38348-9_12"},{"key":"261_CR10","unstructured":"Brainpool. ECC standard. http:\/\/www.ecc-brainpool.org\/ecc-standard.htm"},{"key":"261_CR11","doi-asserted-by":"crossref","unstructured":"Cheng, H., Gro\u00dfsch\u00e4dl, J., Tian, J., R\u00f8nne, P.B., Ryan, P.Y.A.: High-throughput elliptic curve cryptography using AVX2 vector instructions. In Orr Dunkelman and Michael J.\u00a0Jacobson Jr., editors, Selected Areas in Cryptography, 2020, Lecture Notes in Computer Science, (2021). to appear","DOI":"10.1007\/978-3-030-81652-0_27"},{"key":"261_CR12","doi-asserted-by":"crossref","unstructured":"Costello, C., Longa, P.: Four($$\\mathit{Q}$$): Four-dimensional decompositions on a $$\\mathit{Q}$$-curve over the Mersenne prime. In Advances in Cryptology - ASIACRYPT Part I, volume 9452 of Lecture Notes in Computer Science, pp. 214\u2013235. Springer, (2015)","DOI":"10.1007\/978-3-662-48797-6_10"},{"key":"261_CR13","unstructured":"Costello, C., Naehrig, M.: Isogenies between (twisted) Edwards and Montgomery curves. https:\/\/cryptosith.org\/papers\/isogenies_tEd2Mont.pdf, 2015. Accessed on 16 September, (2019)"},{"issue":"3","key":"261_CR14","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s13389-017-0157-6","volume":"8","author":"Craig Costello","year":"2018","unstructured":"Costello, Craig, Benjamin, S.: Montgomery curves and their arithmetic\u2014the case of large characteristic fields. J. Cryptogr. Eng. 8(3), 227\u2013240 (2018)","journal-title":"J. Cryptogr. Eng."},{"key":"261_CR15","unstructured":"Curves NIST. Recommended elliptic curves for federal government use. http:\/\/csrc.nist.gov\/groups\/ST\/toolkit\/documents\/dss\/NISTReCur.pdf, (1999)"},{"key":"261_CR16","doi-asserted-by":"publisher","first-page":"393","DOI":"10.1090\/S0273-0979-07-01153-6","volume":"44","author":"Harold M Edwards","year":"2007","unstructured":"Edwards, Harold M.: A normal form for elliptic curves. Bull. Am. Math. Soc. 44, 393\u2013422 (2007)","journal-title":"Bull. Am. Math. Soc."},{"key":"261_CR17","doi-asserted-by":"crossref","unstructured":"Erbsen, A., Philipoom, J., Gross, J., Sloan, R., Chlipala, A.: Simple high-level code for cryptographic arithmetic\u2014with proofs, without compromises. In 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19\u201323, 2019, pp. 1202\u20131219. IEEE, (2019)","DOI":"10.1109\/SP.2019.00005"},{"issue":"3","key":"261_CR18","doi-asserted-by":"publisher","first-page":"25:1","DOI":"10.1145\/3309759","volume":"45","author":"A Faz-Hern\u00e1ndez","year":"2019","unstructured":"Faz-Hern\u00e1ndez, A., Hernandez, J., Dahab, R.: High-performance implementation of elliptic curve cryptography using vector instructions. ACM Trans. Math. Softw. 45(3), 25:1\u201325:35 (2019)","journal-title":"ACM Trans. Math. Softw."},{"issue":"2","key":"261_CR19","doi-asserted-by":"publisher","first-page":"246","DOI":"10.1016\/j.ffa.2008.12.006","volume":"15","author":"P Gaudry","year":"2009","unstructured":"Gaudry, P., Lubicz, D.: The arithmetic of characteristic 2 Kummer surfaces and of elliptic Kummer lines. Finite Fields Appl. 15(2), 246\u2013260 (2009)","journal-title":"Finite Fields Appl."},{"issue":"4","key":"261_CR20","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1016\/j.jsc.2011.09.003","volume":"47","author":"P Gaudry","year":"2012","unstructured":"Gaudry, P., Schost, \u00c9.: Genus 2 point counting over prime fields. J. Symb. Comput. 47(4), 368\u2013400 (2012)","journal-title":"J. Symb. Comput."},{"key":"261_CR21","first-page":"625","volume":"2015","author":"Mike Hamburg","year":"2015","unstructured":"Hamburg, Mike: Ed448-goldilocks, a new elliptic curve. IACR Cryptol. ePrint Archive 2015, 625 (2015)","journal-title":"IACR Cryptol. ePrint Archive"},{"issue":"10","key":"261_CR22","doi-asserted-by":"publisher","first-page":"1411","DOI":"10.1109\/TC.2009.61","volume":"58","author":"Darrel Hankerson","year":"2009","unstructured":"Hankerson, Darrel, Koray, K., Menezes, A.: Analyzing the Galbraith-Lin-Scott point multiplication method for elliptic curves over binary fields. IEEE Trans. Comput. 58(10), 1411\u20131420 (2009)","journal-title":"IEEE Trans. Comput."},{"key":"261_CR23","first-page":"388","volume":"2020","author":"H Hisil","year":"2020","unstructured":"Hisil, H., Egrice, B., Yassi, M.: Fast 4 way vectorized ladder for the complete set of montgomery curves. IACR Cryptol. ePrint Arch. 2020, 388 (2020)","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"261_CR24","doi-asserted-by":"crossref","unstructured":"Hisil, H., Wong, K.K.-H., Carter, G., Ed\u00a0D.: Twisted Edwards curves revisited. In Josef Pieprzyk, editor, Advances in Cryptology - ASIACRYPT 2008, 14th International Conference on the Theory and Application of Cryptology and Information Security, Melbourne, Australia, December 7\u201311, 2008. Proceedings, volume 5350 of Lecture Notes in Computer Science, pp. 326\u2013343. Springer, (2008)","DOI":"10.1007\/978-3-540-89255-7_20"},{"issue":"1","key":"261_CR25","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1007\/s00145-019-09320-4","volume":"33","author":"Sabyasachi Karati","year":"2020","unstructured":"Karati, Sabyasachi: Kummer for genus one over prime-order fields. J. Cryptol. 33(1), 92\u2013129 (2020)","journal-title":"J. Cryptol."},{"issue":"177","key":"261_CR26","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1090\/S0025-5718-1987-0866109-5","volume":"48","author":"Neal Koblitz","year":"1987","unstructured":"Koblitz, Neal: Elliptic curve cryptosystems. Math. Comp. 48(177), 203\u2013209 (1987)","journal-title":"Math. Comp."},{"key":"261_CR27","doi-asserted-by":"crossref","unstructured":"Langley, A., Hamburg, M.: Elliptic curves for security. Internet Research Task Force (IRTF), Request for Comments: 7748, https:\/\/tools.ietf.org\/html\/rfc7748, 2016. Accessed on 16 September, (2019)","DOI":"10.17487\/RFC7748"},{"key":"261_CR28","unstructured":"Mail archive. CFRG\/IETF. https:\/\/mailarchive.ietf.org\/arch\/msg\/cfrg\/LQIyeCFGgoROzsx_UBf9cjlsS-A"},{"key":"261_CR29","series-title":"Santa Barbara, California, USA, August 18\u201322, 1985, Proceedings","first-page":"417","volume-title":"Advances in Cryptology\u2014CRYPTO\u201985","author":"Victor S Miller","year":"1985","unstructured":"Miller, Victor S.: Use of elliptic curves in cryptography. Advances in Cryptology\u2014CRYPTO\u201985. Santa Barbara, California, USA, August 18\u201322, 1985, Proceedings, pp. 417\u2013426. Springer, Berlin Heidelberg (1985)"},{"issue":"177","key":"261_CR30","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1090\/S0025-5718-1987-0866113-7","volume":"48","author":"Peter L Montgomery","year":"1987","unstructured":"Montgomery, Peter L.: Speeding the Pollard and elliptic curve methods of factorization. Math. Comput. 48(177), 243\u2013264 (1987)","journal-title":"Math. Comput."},{"key":"261_CR31","doi-asserted-by":"crossref","unstructured":"Nath, K., Sarkar, P.: Efficient 4-way vectorizations of the montgomery ladder. IEEE Transactions on Computers, Feb 2021. https:\/\/ieeexplore.ieee.org\/document\/9359500","DOI":"10.1109\/TC.2021.3060505"},{"key":"261_CR32","first-page":"1304","volume":"2019","author":"Kaushik Nath","year":"2019","unstructured":"Nath, Kaushik, Palash, S.: Reduction modulo $$2^{448}-2^{224}-1$$. IACR Cryptol. ePrint Archive 2019, 1304 (2019)","journal-title":"IACR Cryptol. ePrint Archive"},{"key":"261_CR33","first-page":"956","volume":"2020","author":"Kaushik Nath","year":"2020","unstructured":"Nath, Kaushik, Palash, S.: Constant time Montgomery ladder. IACR Cryptol. ePrint Arch. 2020, 956 (2020)","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"261_CR34","unstructured":"NUMS:\u00a0Nothing up\u00a0my sleeve. https:\/\/tools.ietf.org\/html\/draft-black-tls-numscurves-00"},{"key":"261_CR35","unstructured":"Nath, K., Sarkar, P.: Efficient arithmetic in (pseudo-)Mersenne prime order fields. Advances in Mathematics of Communications, (2020). https:\/\/www.aimsciences.org\/article\/doi\/10.3934\/amc.2020113"},{"key":"261_CR36","doi-asserted-by":"crossref","unstructured":"Oliveira, T., Hernandez, J., Hisil, H\u00fcseyin, F., Armando, R.-H.F.: How to (pre-)compute a ladder\u2014improving the performance of X25519 and X448. In Carlisle Adams and Jan Camenisch, editors, Selected Areas in Cryptography\u2014SAC 2017\u201424th International Conference, Ottawa, ON, Canada, August 16-18, 2017, Revised Selected Papers, volume 10719 of Lecture Notes in Computer Science, pp. 172\u2013191. Springer, (2017)","DOI":"10.1007\/978-3-319-72565-9_9"},{"key":"261_CR37","unstructured":"Ozturk, E., Guilford, J., Gopal, V.: Large integer squaring on Intel architecture processors, intel white paper. https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/white-papers\/large-integer-squaring-ia-paper.pdf, (2013)"},{"key":"261_CR38","unstructured":"Ozturk, E., Guilford, J., Gopal, V., Feghali, W.: New instructions supporting large integer arithmetic on Intel architecture processors, intel white paper. https:\/\/www.intel.com\/content\/dam\/www\/public\/us\/en\/documents\/white-papers\/ia-large-integer-arithmetic-paper.pdf, (2012)"},{"key":"261_CR39","doi-asserted-by":"crossref","unstructured":"Protzenko, J., Parno, B., Fromherz, A., Hawblitzel, C., Polubelova, M., Bhargavan, K., Beurdouche, B., Choi, J., Delignat-Lavaud, A., Fournet, C\u00e9dric, K., Natalia, R., Tahina, R., Aseem, S., Nikhil, W., Christoph\u00a0M., B\u00e9guelin, S.Z.: Evercrypt: A fast, verified, cross-platform cryptographic provider. In 2020 IEEE Symposium on Security and Privacy, SP 2020, San Francisco, CA, USA, May 18\u201321, 2020, pp. 983\u20131002. IEEE, (2020)","DOI":"10.1109\/SP40000.2020.00114"},{"key":"261_CR40","unstructured":"Research Certicom. SEC 2: Recommended elliptic curve domain parameters. http:\/\/www.secg.org\/sec2-v2.pdf, (2010)"},{"key":"261_CR41","unstructured":"Version\u00a01.3 TLS\u00a0Protocol. RFC 8446. https:\/\/datatracker.ietf.org\/doc\/rfc8446\/?include_text=1, 2018. Accessed on 16 September, (2019)"}],"container-title":["Journal of Cryptographic Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-021-00261-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s13389-021-00261-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s13389-021-00261-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,15]],"date-time":"2022-03-15T13:42:22Z","timestamp":1647351742000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s13389-021-00261-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,12]]},"references-count":41,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,4]]}},"alternative-id":["261"],"URL":"https:\/\/doi.org\/10.1007\/s13389-021-00261-y","relation":{},"ISSN":["2190-8508","2190-8516"],"issn-type":[{"value":"2190-8508","type":"print"},{"value":"2190-8516","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,12]]},"assertion":[{"value":"13 August 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 April 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}