On Sun, Dec 14, 2014 at 3:36 PM, Michael Hamburg <[email protected]> wrote:
> The main advantage vs Montgomery x + Edwards x sign is that the encoding I’m 
> working on eliminates the cofactor for most practical purposes.
. . .
> * the isogenous twisted Edwards curve with a’ = -1, d’ = d-1 effectively has 
> complete addition formulas;
> * the wire format supports precisely those points which can actually come out 
> of a legitimate implementation.

These advantages strike me as rather decisive: I'd anticipate
implementers being tempted by the performance of the twisted curve.
_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to