Let
be an elliptic
curve, and
a
point in
of
prime order .
Vélu’s formulæ let us compute a quotient curve
and rational maps
defining a quotient isogeny
in
-operations, where
the
is uniform in
. This article shows
how to compute
,
and
for
in
, using
only
-operations,
where the
is
again uniform in
.
As an application, this article speeds up some computations used in the
isogeny-based cryptosystems CSIDH and CSURF.
Dedicated to the memory of Peter
Lawrence Montgomery