Let $E\!: y^2 = x^3 + ax + b$ be an elliptic curve over a finite field $\mathbb{F}_{\!q}$ of prime characteristic $p$ (mostly, $q = p$ in practice). It is well known that in the $\mathbb{F}_{\!q}$-point group $E(\mathbb{F}_{\!q})$ there is so-called point halving $[2]^{-1}$, the operation inverse to doubling $[2]\!: E(\mathbb{F}_{\!q}) \to E(\mathbb{F}_{\!q})$. Recall that for $P \in E(\mathbb{F}_{\!q})$, the inverse image $[2]^{-1}(P)$ may have from $0$ to $4$ points in $E(\mathbb{F}_{\!q})$ depending on $P$ and on the structure of the $2$-torsion subgroup $E(\mathbb{F}_{\!q})[2]$. Assume that I know how to accelerate finding $[2]^{-1}(P)$ in such a way that this is still much slower than doubling, but my method is faster than the state-of-the-art ones for point halving. Are there real-world applications of point halving to motivate my research? Or is it a waste of time and is it better to focus on other scientific tasks?
$\begingroup$ $\endgroup$
Add a comment |
- The Overflow Blog
-
- Featured on Meta
-
-
Related
Hot Network Questions
- Why use「7つある原発」instead of「7つの原発」
- What does Ben Aaronovitch mean by “…large wading bird…” in the “Stone and Sky?”
- How do we see the whole observable universe?
- Does a Monopoly housing shortage auction have a minimum price?
- How to make a wiggle object in Blender 5.0?
- Calculating two highest maximum values of field in QGIS
- Unexpected "would" that doesn't feel right in this context
- Generating 40kHz, 60kHz, and 77.5kHz square waves with a single MCU's timers
- Is there a difference in military court proceedings that would make it easier to convict the "seditious" congress members?
- After a "zzzzz" buzz, why black screen & no white power indicator light on 4-year-old Dell P2222H monitor?
- What is the power of the purse?
- Mathematical rigor behind renormalization
- The Optimal Way
- Recharge battery when it hits 50% or 5%?
- Is it unethical to mention my PhD Thesis in a double blinded review?
- Is there any weapon that does 1 damage?
- Multiple-output flyback converter in DCM mode?
- Crossing a square pond with beams
- When does a finitely cocontinuous functor induce a monadic adjunction between locally finitely presentable categories?
- Not detained but not free to go
- Short story: jumping to/from FTL travel affects body and mind at different rates
- How far can an infinite number of unit length planks bridge a right-angled gap?
- Game set during an apocalypse where people mutate into tall, black beings
- Is it worthwhile to use events when there’s only one subscriber?