On 1/29/14, Robert Ransom <[email protected]> wrote:

> I would prefer the isomorphism Ed(1, d) -> Mont(*, 4/d - 2), since the
> conversion is both conceptually and technically simpler and there is
> no performance cost to using that Montgomery curve in Montgomery form.

Oops.  The isomorphism is Ed(1, d) -> Mont(*, 4/(1-d) - 2).


Robert Ransom
_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to