On 16-12-2014 18:38, Trevor Perrin wrote:
> So I don't think it's worth much added complexity to have an encoding
> that "eliminates the cofactor for all practical purposes".

Insofar as this proposal could contribute to further fragmentation of elliptic 
curves and point formats, I agree. It has
been a slow process to move to curve25519, despite the near 10 years it has 
been around as the sole non-NIST proposal. A
larger curve that fits right into curve25519's shoes thus makes sense.

That said, I'm excited about this. Mike's idea effectively eliminates cofactors 
from the equation, which makes it
possible to treat all these curves as prime-order. Cofactors are probably one 
of the last technical reasons that keep
Weierstrass curves being considered; this could be a convincing argument to 
finally move away from them.



_______________________________________________
Curves mailing list
[email protected]
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to