求椭圆曲线显式三倍公式及相关参考文献
Got it, I feel your pain—deriving the explicit triple point formula straight from the basic addition formula is a total slog with all those messy polynomial simplifications. Let's break down what you need, starting with the most common curve form used in cryptography and number theory: the short Weierstrass elliptic curve.
Short Weierstrass Curve Definition
We’ll work with the standard non-singular curve:
y² = x³ + a x + b
where the discriminant ( \Delta = -16(4a³ + 27b²) ≠ 0 ) (this ensures the curve has no singular points).
Explicit Triple Point Calculation
For a point ( P = (x, y) ) on the curve:
- If ( y = 0 ): ( P ) is a 2-torsion point, so ( 3P = O ) (the point at infinity).
- If ( y ≠ 0 ): ( 3P = (X, Y) ), with the explicit formulas:
X = (9x⁴ - 6a x² - 36b x + a²) / (4(3x⁴ - 12b x + a²))
A simpler way to arrive here (instead of direct derivation) is to first compute ( 2P ) using the doubling formula, then add ( P ) to ( 2P ) with the standard addition formula—this cuts down on the worst of the polynomial chaos.Y = -(27x⁶ + 9a x⁴ + 108b x³ - 9a² x² - 36ab x - 2a³ - 72b²) / (8y(3x⁴ - 12b x + a²)²)
Resources for More Context
If you need formulas for other curve types (like Edwards, Montgomery, or Jacobi curves), or want to see full derivations, these are go-to references:
- Handbook of Elliptic and Hyperelliptic Curve Cryptography: This is the definitive guide for explicit elliptic curve operations. It includes optimized formulas for triple points (and higher multiples) across all major curve forms, plus detailed derivation steps.
- Elliptic Curves: Number Theory and Cryptography (by Lawrence C. Washington): An accessible textbook that walks through the algebra behind point operations, including how to build triple point formulas from basic addition rules.
内容的提问来源于stack exchange,提问作者k.j.

