[curves] Twist-secure 190-bit and 206-bit Edwards curves

Robert Ransom rransom.8774 at gmail.com
Wed Jan 29 01:01:00 PST 2014

Over GF(2^206 - 5):

twisted Edwards curve, a=-1, d=15687: trace of Frobenius =

Over GF(2^190 - 11):

twisted Edwards curve, a=-1, d=18609: trace of Frobenius =

I don't recommend using these for long-term security, but they could
be useful for authentication in applications where public keys must be
typed in by the user, or for low-bandwidth non-interactive

(I think these are the minimal-parameter curves.  I also collected a
few twist-secure curves with non-minimal parameter, and I have a
boatload of traces over these fields, in case anyone wants them.)

Robert Ransom

