On Thu, Oct 30, 2014 at 12:44 AM, Ben Harris <[email protected]> wrote: > Are there recommended > limits on the small 'c' in Crandall primes? This list is only up to 32, but > many on the SafeCurves list are in the 100s.
It's purely a matter of speed. I.e., large values of 'c' are all mainly due to targeting a specific field-size, rather than a speed/security-optimal field size. Most of the Crandalls in SafeCurves with large 'c' are due to Aranha et al.: http://eprint.iacr.org/2013/647 _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
