2022 Volume 14 Pages 108-110
The square-root Vélu's formula ($\elu$'s formula) is known to be effective way to speed up the computations of higher-degree isogeny used for isogeny-based cryptosystems such as CSIDH and B-SIDH. The original formula was proposed using Montgomery curves, and Moriya et al. then extended it to Edwards curves without specific construction method. In this study, we explicitly show how to construct $\elu$'s formula on Edwards curves. In particular, we provide a method for adjusting for the differences between two resultants. We also compare the computational complexity with the original $\elu$'s formula and find that it is up to 8\% faster.