<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Could you please elaborate on this, or point me to a reference?  According to:<div><br></div><div><a href="https://choucroutage.com/Papers/SideChannelAttacks/ches-2002-joye.pdf">https://choucroutage.com/Papers/SideChannelAttacks/ches-2002-joye.pdf</a></div><div><br></div><div>the Montgomery ladder “is of full generality and applies to any abelian group.”</div><div><br></div><div>Is it really the ladder that is more efficient for Montgomery curves, or is it just the point addition and doubling operations that are more efficient?</div><div><br></div><div>rg<br><div><div><br><div><div>On Jul 8, 2015, at 4:05 PM, Michael Hamburg <<a href="mailto:mike@shiftleft.org">mike@shiftleft.org</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><meta http-equiv="Content-Type" content="text/html charset=windows-1252"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div class="">The Montgomery ladder is significantly simpler and more efficient on Montgomery curves than on short Weierstrass curves.</div><br class=""><div><blockquote type="cite" class=""><div class="">On Jul 8, 2015, at 3:38 PM, Ron Garret <<a href="mailto:ron@flownet.com" class="">ron@flownet.com</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><meta http-equiv="Content-Type" content="text/html charset=windows-1252" class=""><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">“Montgomery curves are attractive because of the ladder method of scalar multiplication”<div class=""><br class=""></div><div class="">Is this actually true?  I was under the impression that the Montgomery ladder was applicable to any kind of elliptic curve.  They just both happen to have been invented by Peter Montgomery.</div><div class=""><br class=""></div><div class="">rg</div><div class=""><br class=""><div class=""><div class="">On Jul 7, 2015, at 8:12 PM, Tony Arcieri <<a href="mailto:bascule@gmail.com" class="">bascule@gmail.com</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite" class=""><div dir="ltr" class=""><div class="gmail_quote"><div dir="ltr" class="">I made this poster for the DEFCON Crypto and Privacy Village. It's intended for audiences of mixed ability levels:</div><div dir="ltr" class=""><br class=""></div><div dir="ltr" class=""><a href="https://i.imgur.com/hwbSRHh.png" class="">https://i.imgur.com/hwbSRHh.png</a><br class=""><div class=""><br class=""></div><div class="">Would appreciate technical feedback on it. If you'd like to suggest copy changes, please consider design constraints (i.e. available room on the page).</div><div class=""><br class=""></div><div class="">Thanks!</div><div class=""><br class=""></div></div></div>-- <br class=""><div class="gmail_signature">Tony Arcieri<br class=""></div>
</div>
_______________________________________________<br class="">Curves mailing list<br class=""><a href="mailto:Curves@moderncrypto.org" class="">Curves@moderncrypto.org</a><br class=""><a href="https://moderncrypto.org/mailman/listinfo/curves" class="">https://moderncrypto.org/mailman/listinfo/curves</a><br class=""></blockquote></div><br class=""></div></div>_______________________________________________<br class="">Curves mailing list<br class=""><a href="mailto:Curves@moderncrypto.org" class="">Curves@moderncrypto.org</a><br class=""><a href="https://moderncrypto.org/mailman/listinfo/curves">https://moderncrypto.org/mailman/listinfo/curves</a><br class=""></div></blockquote></div><br class=""></div></blockquote></div><br></div></div></div></body></html>