[curves] Twist-secure Weierstrass curves over Fq(Sal384)

David Leon Gil coruus at gmail.com
Wed Dec 3 19:09:41 PST 2014


On Sat, Nov 29, 2014 at 6:14 PM, David Leon Gil <coruus at gmail.com> wrote:
> egregious blunders are entirely mine, however.)

Speaking of egregious blunders: those results are incorrect. I was
inadvertently omitting curves with small factors on the twist; the
real probability of a twist-secure curve is somewhat lower.

(For example, the curve with j-invariant 480 has prime order, but its
twist has small factors of 11 and 41; the trace is
0x2469cf14a46eb41c5aacf42bc9d61c9168d12ef701ad0f09. It was not counted
as a curve with prime order.)

Urgh. Re-running.


More information about the Curves mailing list