[curves] Balancing reduced-radix and full-radix performance for extra-strength primes

Mike Hamburg mike at shiftleft.org
Tue Jan 20 10:42:31 PST 2015

On 01/19/2015 08:24 PM, Michael Hamburg wrote:
> On their “comparison” slide did they mention that the Ed448-Goldilocks and E-521 impls both use point compression, and therefore have a 10% penalty vs their Ted37919 numbers?  It seems a little dishonest if they didn’t.
I shouldn't have written this.  I do think it's important to mention 
that the benchmarks are for different operations, and I do think that 
the slide's numbers favor Ted37919.  But the difference is closer than 
I'd initially thought and anyway it's assuming too much to describe this 
as dishonesty.

-- Mike

