[curves] The great debate over point formats

Michael Hamburg mike at shiftleft.org
Tue Jan 28 11:41:28 PST 2014


Do you mean the whole Edwards-x-coordinate, or just the sign?

On Jan 28, 2014, at 11:40 AM, Watson Ladd <watsonbladd at gmail.com> wrote:

> Right now there is a deep question: which point formats should be used
> on Edwards curves? I am leaning towards Robert Ransoms suggestion of
> specifying v coordinates on the isogenous Montgomery curve plus the x
> coordinate of the Edwards curve. This enables a single implementation
> to work for all protocols, if care is taken to discard the sign.
> 
> The one issue is several explicit formulas for isogenous Montgomery
> ladders and conversion need to be worked out.
> 
> Sincerely,
> Watson Ladd
> _______________________________________________
> Curves mailing list
> Curves at moderncrypto.org
> https://moderncrypto.org/mailman/listinfo/curves



More information about the Curves mailing list