[curves] The great debate over point formats

Watson Ladd watsonbladd at gmail.com
Tue Jan 28 11:44:14 PST 2014


On Tue, Jan 28, 2014 at 11:41 AM, Michael Hamburg <mike at shiftleft.org> wrote:
> Do you mean the whole Edwards-x-coordinate, or just the sign?

Good catch: just the sign is probably the best choice.

>
> On Jan 28, 2014, at 11:40 AM, Watson Ladd <watsonbladd at gmail.com> wrote:
>
>> Right now there is a deep question: which point formats should be used
>> on Edwards curves? I am leaning towards Robert Ransoms suggestion of
>> specifying v coordinates on the isogenous Montgomery curve plus the x
>> coordinate of the Edwards curve. This enables a single implementation
>> to work for all protocols, if care is taken to discard the sign.
>>
>> The one issue is several explicit formulas for isogenous Montgomery
>> ladders and conversion need to be worked out.
>>
>> Sincerely,
>> Watson Ladd
>> _______________________________________________
>> Curves mailing list
>> Curves at moderncrypto.org
>> https://moderncrypto.org/mailman/listinfo/curves
>



-- 
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin


More information about the Curves mailing list