[curves] Point formats (also, genus 3 coming soon!)

Watson Ladd watsonbladd at gmail.com
Wed Mar 19 18:59:10 PDT 2014

Dear all,

Kim Laine has something to say about genus three curves. I don't know
what it is, but will report when I hear it in two weeks.

On the genus 1 front, what sort of properties do implementors expect
from point formats? Mike Hamburg argues it's fine to not have a
bijection, so long as round tripping from point to encoded format to
point gives the same point on a big encodable subset (think E[q](K),
not all the rational points. That is, we throw out some small-order
points).  I'm starting to come around to this idea, but some of the
formats are just wonky and require quite a bit of thought to
understand or don't work for curve25519, or both. Does anyone have
explicit formulas for clever formats?


