On Sun, Dec 14, 2014 at 3:36 PM, Michael Hamburg <[email protected]> wrote: > The main advantage vs Montgomery x + Edwards x sign is that the encoding I’m > working on eliminates the cofactor for most practical purposes. . . . > * the isogenous twisted Edwards curve with a’ = -1, d’ = d-1 effectively has > complete addition formulas; > * the wire format supports precisely those points which can actually come out > of a legitimate implementation.
These advantages strike me as rather decisive: I'd anticipate implementers being tempted by the performance of the twisted curve. _______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
