“…As the problem of finding the shortest addition chain is NPcomplete [17], practical algorithms for exponentiation without a division operation have been studied such as the binary method, the m-ary method, window methods [31,34,41,52], exponent-folding methods [33,49], and precomputation methods [7,32]. For a group where the inversion operation is efficient like elliptic curve cryptosystems [30,35], an addition-subtraction chain can yield a good performance [38].…”