Invalid-curve attacks on (hyper)elliptic curve cryptosystems

Koray Karabina, Berkant Ustaoğlu · Advances in Mathematics of Communications · 2010

We extend the notion of an invalid-curve attack from elliptic curvesto genus 2 hyperelliptic curves. We also show that invalid singular (hyper)ellipticcurves can be used in mounting invalid-curve attacks on (hyper)elliptic curvecryptosystems, and make quantitative estimates of the practicality of theseattacks. We thereby show that proper key validation is necessary even in cryptosystemsbased on hyperelliptic curves. As a byproduct, we enumerate theisomorphism classes of genus g hyperelliptic curves over a finite field by a newcounting argument that is simpler than the previous methods.

Read the paper · More papers on PaperTik