Hi, I'm currently working on a CramerShoup implementation using decaf_448, Whereas decaf is to eliminate the cofactor by compression, Should I still use the equation "orderQ*cofactor*P == identity" to check the candidate generator P? Or, What should be a "valid" generator mean in this use case?
Thanks, Fan
_______________________________________________ Curves mailing list [email protected] https://moderncrypto.org/mailman/listinfo/curves
