{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T23:19:32Z","timestamp":1773962372001,"version":"3.50.1"},"reference-count":33,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2022,5,26]],"date-time":"2022-05-26T00:00:00Z","timestamp":1653523200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Math. Softw."],"published-print":{"date-parts":[[2022,6,30]]},"abstract":"<jats:p>This paper makes a comprehensive comparison of the efficiencies of vectorized implementations of Kummer lines and Montgomery curves at various security levels. For the comparison, nine Kummer lines are considered, out of which eight are new, and new assembly implementations of all nine Kummer lines have been made. Seven previously proposed Montgomery curves are considered and new vectorized assembly implementations have been made for three of them. Our comparisons show that for all security levels, Kummer lines are consistently faster than Montgomery curves, though the speed-up gap is not much.<\/jats:p>","DOI":"10.1145\/3503536","type":"journal-article","created":{"date-parts":[[2022,2,11]],"date-time":"2022-02-11T17:45:12Z","timestamp":1644601512000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Kummer versus Montgomery Face-off over Prime Order Fields"],"prefix":"10.1145","volume":"48","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8159-4589","authenticated-orcid":false,"given":"Kaushik","family":"Nath","sequence":"first","affiliation":[{"name":"Indian Statistical Institute, Kolkata, West Bengal, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5346-2650","authenticated-orcid":false,"given":"Palash","family":"Sarkar","sequence":"additional","affiliation":[{"name":"Indian Statistical Institute, Kolkata, West Bengal, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,5,26]]},"reference":[{"key":"e_1_3_3_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/0021-8693(69)90117-3"},{"key":"e_1_3_3_3_2","article-title":"Can we avoid tests for zero in fast elliptic-curve arithmetic?","author":"Bernstein Daniel J.","year":"2006","unstructured":"Daniel J. Bernstein. 2006. Can we avoid tests for zero in fast elliptic-curve arithmetic? https:\/\/cr.yp.to\/ecdh\/curvezero-20060726.pdf. Accessed on 16 September, 2019.","journal-title":"https:\/\/cr.yp.to\/ecdh\/curvezero-20060726.pdf"},{"key":"e_1_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/11745853_14"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68164-9_26"},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-012-0027-1"},{"key":"e_1_3_3_7_2","article-title":"SafeCurves: Choosing safe curves for elliptic-curve cryptography","author":"Bernstein D. J.","unstructured":"D. J. Bernstein and T. Lange. [n.d.]. SafeCurves: Choosing safe curves for elliptic-curve cryptography. http:\/\/safecurves.cr.yp.to\/index.html. accessed on November 04, 2020.","journal-title":"http:\/\/safecurves.cr.yp.to\/index.html. accessed on November 04, 2020"},{"key":"e_1_3_3_8_2","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1017\/9781316271575.005","volume-title":"Topics in Computational Number Theory inspired by Peter L. Montgomery","author":"Bernstein Daniel J.","year":"2017","unstructured":"Daniel J. Bernstein and Tanja Lange. 2017. Montgomery curves and the Montgomery ladder. In Topics in Computational Number Theory inspired by Peter L. Montgomery, Joppe W. Bos and Arjen K. Lenstra (Eds.). Cambridge University Press, 82\u2013115."},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33027-8_19"},{"key":"e_1_3_3_10_2","article-title":"Crible Alg\u00e9brique: Distribution, Optimisation - Number Field Sieve","year":"2006","unstructured":"CADO-NFS. 2006. Crible Alg\u00e9brique: Distribution, Optimisation - Number Field Sieve. Available at http:\/\/cado-nfs.gforge.inria.fr. Accessed on 27 January, 2021.","journal-title":"Available at http:\/\/cado-nfs.gforge.inria.fr"},{"key":"e_1_3_3_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-31301-6_8"},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13389-017-0157-6"},{"key":"e_1_3_3_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3309759"},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF01186653"},{"key":"e_1_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1515\/JMC.2007.012"},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ffa.2008.12.006"},{"key":"e_1_3_3_18_2","first-page":"625","article-title":"Ed448-Goldilocks, a new elliptic curve","volume":"2015","author":"Hamburg Mike","year":"2015","unstructured":"Mike Hamburg. 2015. Ed448-Goldilocks, a new elliptic curve. IACR Cryptology ePrint Archive 2015 (2015), 625. http:\/\/eprint.iacr.org\/2015\/625.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_3_19_2","first-page":"388","article-title":"Fast 4 way vectorized ladder for the complete set of Montgomery curves","volume":"2020","author":"Hisil H\u00fcseyin","year":"2020","unstructured":"H\u00fcseyin Hisil, Berkan Egrice, and Mert Yassi. 2020. Fast 4 way vectorized ladder for the complete set of Montgomery curves. IACR Cryptology ePrint Archive 2020 (2020), 388. https:\/\/eprint.iacr.org\/2020\/388.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.3934\/amc.2019003"},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-019-09320-4"},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"e_1_3_3_23_2","article-title":"Elliptic Curves for Security","author":"Langley Adam","year":"2016","unstructured":"Adam Langley and Mike Hamburg. 2016. Elliptic Curves for Security. Internet Research Task Force (IRTF), Request for Comments: 7748, https:\/\/tools.ietf.org\/html\/rfc7748. Accessed on 16 September, 2019.","journal-title":"Internet Research Task Force (IRTF), Request for Comments: 7748, https:\/\/tools.ietf.org\/html\/rfc7748"},{"key":"e_1_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39799-X_31"},{"key":"e_1_3_3_25_2","doi-asserted-by":"publisher","DOI":"10.1090\/S0025-5718-1987-0866113-7"},{"key":"e_1_3_3_26_2","first-page":"1304","article-title":"Reduction modulo  \\( 2^{448}-2^{224}-1 \\)","volume":"2019","author":"Nath Kaushik","year":"2019","unstructured":"Kaushik Nath and Palash Sarkar. 2019. Reduction modulo \\( 2^{448}-2^{224}-1 \\) . IACR Cryptology ePrint Archive 2019 (2019), 1304. https:\/\/eprint.iacr.org\/2019\/1304.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_3_27_2","first-page":"1259","article-title":"Security and efficiency trade-offs for elliptic curve Diffie-Hellman at the 128-bit and 224-bit security levels","volume":"2019","author":"Nath Kaushik","year":"2019","unstructured":"Kaushik Nath and Palash Sarkar. 2019. Security and efficiency trade-offs for elliptic curve Diffie-Hellman at the 128-bit and 224-bit security levels. IACR Cryptol. ePrint Arch. 2019 (2019), 1259. https:\/\/eprint.iacr.org\/2019\/1259.","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_3_28_2","first-page":"956","article-title":"Constant time Montgomery ladder","volume":"2020","author":"Nath Kaushik","year":"2020","unstructured":"Kaushik Nath and Palash Sarkar. 2020. Constant time Montgomery ladder. IACR Cryptol. ePrint Arch. 2020 (2020), 956. https:\/\/eprint.iacr.org\/2020\/956.","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_3_29_2","first-page":"378","article-title":"Efficient 4-way vectorizations of the Montgomery ladder","volume":"2020","author":"Nath Kaushik","year":"2020","unstructured":"Kaushik Nath and Palash Sarkar. 2020. Efficient 4-way vectorizations of the Montgomery ladder. IACR Cryptology ePrint Archive 2020 (2020), 378. https:\/\/eprint.iacr.org\/2020\/378.","journal-title":"IACR Cryptology ePrint Archive"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.3934\/amc.2020113"},{"key":"e_1_3_3_31_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2019.0620"},{"key":"e_1_3_3_32_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-72565-9_9"},{"key":"e_1_3_3_33_2","article-title":"RFC 8446","author":"Protocol Version 1.3 TLS","year":"2018","unstructured":"Version 1.3 TLS Protocol. 2018. RFC 8446. https:\/\/datatracker.ietf.org\/doc\/rfc8446\/?include_text=1. Accessed on 16 September, 2019.","journal-title":"https:\/\/datatracker.ietf.org\/doc\/rfc8446\/?include_text=1"},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.4324\/9780203484029"}],"container-title":["ACM Transactions on Mathematical Software"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503536","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503536","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:19Z","timestamp":1750186939000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503536"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,26]]},"references-count":33,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,6,30]]}},"alternative-id":["10.1145\/3503536"],"URL":"https:\/\/doi.org\/10.1145\/3503536","relation":{},"ISSN":["0098-3500","1557-7295"],"issn-type":[{"value":"0098-3500","type":"print"},{"value":"1557-7295","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,5,26]]},"assertion":[{"value":"2021-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-05-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}