[curves] The great debate over point formats

Paulo S. L. M. Barreto pbarreto at larc.usp.br
Thu Jan 30 03:15:03 PST 2014

Hello to all,

On Wed Jan 29 18:07:34 PST 2014, Robert Ransom <rransom.8774 at gmail.com> wrote:

> My main problem with the ‘Brazil’ curves is that all of them except
> M-221 (even the E-* curves) have really *ugly* coordinate fields.
> They make the NSA fields look nice by comparison (and at least those
> would have the advantage of requiring less extra hardware within a
> TPM, as someone mentioned on one of the IETF lists

I'm just now coming back from vacations so this message is very brief, but you
got my attention. Could you please state your 'beauty' metric quantitatively?
Also, the curve over F_{2^521 - 1} (which was, in a different form,
independently discovered by Mike Hamburg, and then also by Dan Bernstein and
Tanja Lange) is ugly?



