Real hyperelliptic curve explained

g\geq1

. The general formula of Hyperelliptic curve over a finite field

K

is given by C : y^2 + h(x) y = f(x) \in K[x,y]where

h(x),f(x)\inK

satisfy certain conditions. In this page, we describe more about real hyperelliptic curves, these are curves having two points at infinity while imaginary hyperelliptic curves have one point at infinity.

Definition

A real hyperelliptic curve of genus g over K is defined by an equation of the form

C:y2+h(x)y=f(x)

where

h(x)\inK

has degree not larger than g+1 while

f(x)\inK

must have degree 2g+1 or 2g+2. This curve is a non singular curve where no point

(x,y)

in the algebraic closure of

K

satisfies the curve equation

y2+h(x)y=f(x)

and both partial derivative equations:

2y+h(x)=0

and

h'(x)y=f'(x)

. The set of (finite)

K

–rational points on C is given byC(K) = \left\ \cup S where

S

is the set of points at infinity. For real hyperelliptic curves, there are two points at infinity,

infty1

and

infty2

. For any point

P(a,b)\inC(K)

, the opposite point of

P

is given by

\overline{P}=(a,-b-h)

; it is the other point with x-coordinate a that also lies on the curve.

Example

Let

C:y2=f(x)

wheref(x) = x^6 +3x^5 - 5x^4 - 15x^3 + 4x^2 + 12x = x(x-1)(x-2)(x+1)(x+2)(x+3) over

R

. Since

\degf(x)=2g+2

and

f(x)

has degree 6, thus

C

is a curve of genus g = 2.

The homogeneous version of the curve equation is given byY^2 Z^4 = X^6 + 3 X^5 Z - 5 X^4 Z^2 - 15 X^3 Z^3 + 4X^2 Z^4 + 12X Z^5.It has a single point at infinity given by (0:1:0) but this point is singular. The blowup of

C

has 2 different points at infinity, which we denote

infty1

and

infty2

. Hence this curve is an example of a real hyperelliptic curve.

In general, every curve given by an equation where f has even degree has two points at infinity and is a real hyperelliptic curve while those where f has odd degree have only a single point in the blowup over (0:1:0) and are thus imaginary hyperelliptic curves. In both cases this assumes that the affine part of the curve is non-singular (see the conditions on the derivatives above)

Arithmetic in a real hyperelliptic curve

In real hyperelliptic curve, addition is no longer defined on points as in elliptic curves but on divisors and the Jacobian. Let

C

be a hyperelliptic curve of genus g over a finite field K. A divisor

D

on

C

is a formal finite sum of points

P

on

C

. We writeD = \sum_ where

nP\in\Z

and

np=0

for almost all

P

.

The degree of D= \sum_ is defined by \deg(D) = \sum_.

D

is said to be defined over

K

if D^\sigma = \sum_n_P P^\sigma = D for all automorphisms σ of

\overline{K}

over

K

. The set

Div(K)

of divisors of

C

defined over

K

forms an additive abelian group under the addition rule \sum a_P P + \sum b_P P = \sum .

The set

Div0(K)

of all degree zero divisors of

C

defined over

K

is a subgroup of

Div(K)

.

We take an example:

Let

D1=6P1+4P2

and

D2=1P1+5P2

. If we add them then

D1+D2=7P1+9P2

. The degree of

D1

is

\deg(D1)=6+4=10

and the degree of

D2

is

\deg(D2)=1+5=6

. Then,

\deg(D1+D2)=\deg(D1)+\deg(D2)=16.

For polynomials

G\inK[C]

, the divisor of

G

is defined by\mathrm(G)=\sum_ _P(G)P.If the function

G

has a pole at a point

P

then

-{ord

}_P (G) is the order of vanishing of

G

at

P

. Assume

G,H

are polynomials in

K[C]

; the divisor of the rational function

F=G/H

is called a principal divisor and is defined by

div(F)=div(G)-div(H)

. We denote the group of principal divisors by

P(K)

, i.e.,

P(K)=\{div(F)\midF\inK(C)\}

. The Jacobian of

C

over

K

is defined by

J=Div0/P

. The factor group

J

is also called the divisor class group of

C

. The elements which are defined over

K

form the group

J(K)

. We denote by

\overline{D}\inJ(K)

the class of

D

in

Div0(K)/P(K)

.

There are two canonical ways of representing divisor classes for real hyperelliptic curves

C

which have two points infinity

S=\{infty1,infty2\}

. The first one is to represent a degree zero divisor by

\bar{D}

such that D=\sum_^r P_i-r\infty_2, where

Pi\inC(\bar{F

}_q),

Pi\not=infty2

, and

Pi\not=\bar{Pj}

if

ij

The representative

D

of

\bar{D}

is then called semi reduced. If

D

satisfies the additional condition

r\leqg

then the representative

D

is called reduced.[1] Notice that

Pi=infty1

is allowed for some i. It follows that every degree 0 divisor class contain a unique representative

\bar{D}

with D= D_x-\deg(D_x) \infty_2+v_1 (D)(\infty_1-\infty_2),where

Dx

is divisor that is coprime with both

infty1

and

infty2

, and

0\leq\deg(Dx)+v1(D)\leqg

.

The other representation is balanced at infinity. Let

Dinfty=infty1+infty2

, note that this divisor is

K

-rational even if the points

infty1

and

infty2

are not independently so. Write the representative of the class

\bar{D}

as

D=D1+Dinfty

,where

D1

is called the affine part and does not contain

infty1

and

infty2

, and let

d=\deg(D1)

. If

d

is even thenD_\infty= \frac(\infty_1+\infty_2).

If

d

is odd then D_\infty= \frac \infty_1+\frac \infty_2.For example, let the affine parts of two divisors be given by

D1=6P1+4P2

and

D2=1P1+5P2

then the balanced divisors are

D1=6P1+4P2-

5D
infty1
-5D
infty2

and

D2=1P1+5P2-

3D
infty1
-3D
infty2

Transformation from real hyperelliptic curve to imaginary hyperelliptic curve

Let

C

be a real quadratic curve over a field

K

. If there exists a ramified prime divisor of degree 1 in

K

then we are able to perform a birational transformation to an imaginary quadratic curve.A (finite or infinite) point is said to be ramified if it is equal to its own opposite. It means that

P=(a,b)=\overline{P}=(a,-b-h(a))

, i.e. that

h(a)+2b=0

. If

P

is ramified then

D=P-infty1

is a ramified prime divisor.[2]

The real hyperelliptic curve

C:y2+h(x)y=f(x)

of genus

g

with a ramified

K

-rational finite point

P=(a,b)

is birationally equivalent to an imaginary model

C':y'2+\bar{h}(x')y'=\bar{f}(x')

of genus

g

, i.e.

\deg(\bar{f})=2g+1

and the function fields are equal

K(C)=K(C')

.[3] Here:

In our example

C:y2=f(x)

where

f(x)=x6+3x5-5x4-15x3+4x2+12x

, h(x) is equal to 0. For any point

P=(a,b)

,

h(a)

is equal to 0 and so the requirement for P to be ramified becomes

b=0

. Substituting

h(a)

and

b

, we obtain

f(a)=0

, where

f(a)=a(a-1)(a-2)(a+1)(a+2)(a+3)

, i.e.,

a\in\{0,1,2,-1,-2,-3\}

.

From, we obtain x= \frac and y= \frac. For g = 2, we have y = \frac.

For example, let

a=1

then x= \frac and y= \frac , we obtain \left(\frac\right)^2=\frac \left(\frac +1\right)\left(\frac +2\right)\left(\frac +3\right)\left(\frac -1\right)\left(\frac -2\right).

To remove the denominators this expression is multiplied by

x6

, then: y'^2=(x'+1)(2x'+1)(3x'+1)(4x'+1)(1)(1-x') giving the curve C' : y'^2 = \bar(x') where \bar(x') = (x'+1) (2x'+1) (3x'+1) (4x'+1) (1) (1-x') = -24x'^5-26x'^4 + 15x'^3 + 25x'^2 + 9x'+1 .

C'

is an imaginary quadratic curve since

\bar{f}(x')

has degree

2g+1

.

Notes and References

  1. Erickson . Stefan . Jacobson . Michael J., Jr. . Stein . Andreas . 10.3934/amc.2011.5.623 . 4 . Advances in Mathematics of Communications . 2855275 . 623–666 . Explicit formulas for real hyperelliptic curves of genus 2 in affine representation . 5 . 2011.
  2. Jacobson . Michael J. Jr. . Scheidler . Renate . Renate Scheidler . Stein . Andreas . 10.2478/v10127-010-0030-9 . Tatra Mountains Mathematical Publications . 2791633 . 31–65 . Cryptographic aspects of real hyperelliptic curves . 47 . 2010.
  3. Galbraith . Steven D. . Lin . Xibin . Morales . David J. Mireles . Galbraith . Steven D. . Paterson . Kenneth G. . Pairings on hyperelliptic curves with a real model . https://eprint.iacr.org/2008/250 . 10.1007/978-3-540-85538-5_18 . 2733918 . 265–281 . Springer . Lecture Notes in Computer Science . Pairing-Based Cryptography – Pairing 2008, Second International Conference, Egham, UK, September 1–3, 2008. Proceedings . 5209 . 2008.