4 ms·
> we now have better ways of dealing with short Weierstraß curves We do? The complete Renes/Costello/Batina formulas for point addition are significantly slowe
by beefhash 6y ago
> we now have better ways of dealing with short Weierstraß curves
We do? The complete Renes/Costello/Batina formulas for point addition are significantly slower at a factor of 1.4.[1] The complete formulas presented by Hamburg are still somewhat slower than what you can get on twisted Edwards and almost certain to be patent encumbered by the end of the year.[2] Did I miss something?
SafeCurves discounts Renes/Costello/Batina and the like because “many of these formulas are considerably slower and more complicated than standard incomplete scalar-multiplication formulas, creating major conflicts between simplicity, efficiency, and security”.[3]
[1] https://cryptojedi.org/papers/complete1-20191011.pdf https://cryptojedi.org/papers/complete1-20191011.pdf
[2] https://eprint.iacr.org/2020/437 https://eprint.iacr.org/2020/437
[3] https://safecurves.cr.yp.to/complete.html https://safecurves.cr.yp.to/complete.html
- loup-vaillant 6y agoCorrect, but my point was that even if they're slower, we do have complete formulas that aren't the nightmare djb describes. I do reckon however that having to chose between speed and safety is a big problem. Someone is bound to go the fast route and screw up some special case, or leak timing information. I didn't know about possible patents, that sucks. (I live in the EU though, so I can still give them the finger if I need to.) In any case, the best general purpose thing we have now is probably Decaf/Ristretto over (twisted) Edwards curves. Fast complete formulas and a prime order group. Dealing with the cofactor is not too hard, but it's not trivial either: http://loup-vaillant.fr/tutorials/cofactor http://loup-vaillant.fr/tutorials/cofactor (I still love Montgomery curves for variable base scalar multiplication.)
- beefhash 6y ago> I didn't know about possible patents, that sucks. (I live in the EU, though, so I can still give them the finger if I need to.) Hamburg made this IP risk pretty clear in the paper, for a bit more context on it, see [1]. Because in the U.S. you have a full year before you even need to file a patent after publishing, we'll still have to wait and see if Hamburg's employer files a patent on his method. If they don't, nice; if they do, fucking hell this is why we can't have nice things. Renes/Costello/Batina is unencumbered as far as I know. [1] https://www.reddit.com/r/crypto/comments/g46pft/_/fnwp9p2/?context=3 https://www.reddit.com/r/crypto/comments/g46pft/_/fnwp9p2/?c...