[curves] Balancing reduced-radix and full-radix performance for extra-strength primes
    Trevor Perrin 
    trevp at trevp.net
       
    Mon Jan 19 20:58:27 PST 2015
    
    
  
On Mon, Jan 19, 2015 at 6:24 PM, Michael Hamburg <mike at shiftleft.org> wrote:
>
> On their “comparison” slide did they mention that the Ed448-Goldilocks and E-521 impls both use point compression, and therefore have a 10% penalty vs their Ted37919 numbers?  It seems a little dishonest if they didn’t.
I don't recall that being mentioned.  He probably assumed it was just
timing an x-coordinate Montgomery ladder, and didn't expect your
special point format.
(Maybe you should submit just an x-coordinate ladder to SUPERCOP.  I'd
like to see the numbers without decompression, this is inaccurate in
my spreadsheet too.)
Trevor
    
    
More information about the Curves
mailing list