3 ms·
The details of the curve, the finite field, and point P are chosen ahead of time (at least with modern curves… you used to be able to choose a custom P and it l
by syncsynchalt 3y ago
The details of the curve, the finite field, and point P are chosen ahead of time (at least with modern curves… you used to be able to choose a custom P and it led to security flaws). When we refer to something like “X25519” or “NIST P256” it means the combined set of all three things.
In TLS terms the client connects and says “is X25519 good? I can also do these other curves” and the server either agrees or chooses another curve in its response.
- syncsynchalt 3y agoI’ve just reread my reply and could have been clearer: the curve, finite field, and base point are chosen ahead of time _by the standards body_. When two endpoints agree to use e.g. the NIST P-256 curve, then they are agreeing on the curve equation, the finite field, and the base point, all together as a set of items.
- bryan0 3y agoNo worries your initial response was clear to me. My question was under the assumption that you couldn’t mathematically pick an arbitrary pair of curve and finite field, but I guess any choice is fine as long as the parties agree ahead of time.