[curves] Twist-secure 190-bit and 206-bit Edwards curves

Robert Ransom rransom.8774 at gmail.com
Wed Jan 29 01:01:00 PST 2014


Over GF(2^206 - 5):

twisted Edwards curve, a=-1, d=15687: trace of Frobenius =
10926092737692135979572174042232


Over GF(2^190 - 11):

twisted Edwards curve, a=-1, d=18609: trace of Frobenius =
46868259482470880298307215470


I don't recommend using these for long-term security, but they could
be useful for authentication in applications where public keys must be
typed in by the user, or for low-bandwidth non-interactive
steganography.

(I think these are the minimal-parameter curves.  I also collected a
few twist-secure curves with non-minimal parameter, and I have a
boatload of traces over these fields, in case anyone wants them.)


Robert Ransom


More information about the Curves mailing list