[curves] The Pareto frontiers of sleeveless primes
David Leon Gil
coruus at gmail.com
Thu Oct 30 06:58:10 PDT 2014
On Thu, Oct 30, 2014 at 12:44 AM, Ben Harris <mail at bharr.is> wrote:
> Are there recommended
> limits on the small 'c' in Crandall primes? This list is only up to 32, but
> many on the SafeCurves list are in the 100s.
It's purely a matter of speed.
I.e., large values of 'c' are all mainly due to targeting a specific
field-size, rather than a speed/security-optimal field size.
Most of the Crandalls in SafeCurves with large 'c' are due to Aranha
et al.: http://eprint.iacr.org/2013/647
More information about the Curves
mailing list