[curves] The great debate over point formats

Watson Ladd watsonbladd at gmail.com
Tue Jan 28 11:40:35 PST 2014


Right now there is a deep question: which point formats should be used
on Edwards curves? I am leaning towards Robert Ransoms suggestion of
specifying v coordinates on the isogenous Montgomery curve plus the x
coordinate of the Edwards curve. This enables a single implementation
to work for all protocols, if care is taken to discard the sign.

The one issue is several explicit formulas for isogenous Montgomery
ladders and conversion need to be worked out.

Sincerely,
Watson Ladd


More information about the Curves mailing list