On 1/29/14, Robert Ransom <[email protected]> wrote: > I would prefer the isomorphism Ed(1, d) -> Mont(*, 4/d - 2), since the > conversion is both conceptually and technically simpler and there is > no performance cost to using that Montgomery curve in Montgomery form.
Oops. The isomorphism is Ed(1, d) -> Mont(*, 4/(1-d) - 2). Robert Ransom _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
