[curves] Comparing high-speed / high-security curve implementations

Ben Smith hyperelliptic at gmail.com
Wed Apr 23 13:05:04 PDT 2014


2014-04-23 21:48 GMT+02:00 Trevor Perrin <trevp at trevp.net>:
> I'm not sure I'm comparing apples-to-apples anymore (GLS curves?

GLS curves are nice.  They lack twist-security (by construction)
though, which is relevant in the context of ECDH implementations.

[1] http://safecurves.cr.yp.to/twist.html


ben

-- 
You know we all became mathematicians for the same reason: we were lazy.
  --Max Rosenlicht


More information about the Curves mailing list