Robert Granger and Michael Scott report a fast E-521 implementation: http://eprint.iacr.org/2014/852
Based on Haswell numbers, its efficiency seems similar to Goldilocks: https://docs.google.com/a/trevp.net/spreadsheet/ccc?key=0Aiexaz_YjIpddFJuWlNZaDBvVTRFSjVYZDdjakxoRkE&usp=sharing#gid=0 DJB also timed it on Sandy Bridge, though his numbers are worse than I'd expect; not sure why: http://www.ietf.org/mail-archive/web/cfrg/current/msg05349.html Trevor _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
