5 ms·
How are the curves defined? Is there a 'standard' curve that's generally used or is the curve itself randomly generated along with the keys?
by LennyWhiteJr 6y ago
How are the curves defined? Is there a 'standard' curve that's generally used or is the curve itself randomly generated along with the keys?
- bannerts 6y agohttps://en.bitcoin.it/wiki/Secp256k1 https://en.bitcoin.it/wiki/Secp256k1 For example with bitcoin
- layoutIfNeeded 6y agoThe curve is fixed. The de facto curve nowadays is Curve25519. https://en.m.wikipedia.org/wiki/Curve25519 https://en.m.wikipedia.org/wiki/Curve25519
- tptacek 6y agoYou can generate new curve parameters, but nobody does, and you shouldn't (you will perish in flames). The popular curves, probably in order of popularity, are the NIST P-Curves (like P-256), Curve25519 (and Ed25519 for signing), Bitcoin's secp256k1 (originally from Certicom), and then higher-security-margin curves like E-521.
- zahllos 6y agoE-521 is a popular curve? Are you sure you don't mean P-521? I mean I'm all for the Edwards variant but I'm fairly sure most people haven't heard of it and I'm not aware of a single popular crypto library that implements it.
- tptacek 6y agoSure, P-521, whatever. I make no claims to accurately ranking curve popularity, except I am pretty sure as a practitioner (not a cryptographer) that the P-curves are still the most popular, and that 25519 and its variants are close behind. Curve448, the Hamburg specification? That's got to fit in there somewhere too? (I'm not trying to be snarky, just sort of expressing the sentiment of throwing up my hands after having a grip on P-256 and Curve25519).
- zahllos 6y agoI also didn't mean to be snarky, but E-521 is far too estoric a choice to be casually dropped in without comment. I am fairly sure BLS curves see more use :) If we're not careful some hodlgang hooligan will have this implemented (badly) in Rust in 30 seconds!