Re: [Cfrg] Elliptic Curves - poll on specific curve around 256bit work factor (ends on February 23rd)

Michael Hamburg <mike@shiftleft.org> Mon, 23 February 2015 22:29 UTC

Return-Path: <mike@shiftleft.org>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B86D81A0235 for <cfrg@ietfa.amsl.com>; Mon, 23 Feb 2015 14:29:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.556
X-Spam-Level: *
X-Spam-Status: No, score=1.556 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FH_HOST_EQ_D_D_D_D=0.765, FH_HOST_EQ_D_D_D_DB=0.888, HELO_MISMATCH_ORG=0.611, HOST_MISMATCH_NET=0.311, HTML_MESSAGE=0.001, RDNS_DYNAMIC=0.982, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kMwLW6YgHzOa for <cfrg@ietfa.amsl.com>; Mon, 23 Feb 2015 14:29:22 -0800 (PST)
Received: from aspartame.shiftleft.org (199-116-74-168-v301.PUBLIC.monkeybrains.net [199.116.74.168]) (using TLSv1.1 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 988181A0199 for <cfrg@irtf.org>; Mon, 23 Feb 2015 14:29:22 -0800 (PST)
Received: from [10.184.148.249] (unknown [209.36.6.242]) by aspartame.shiftleft.org (Postfix) with ESMTPSA id 1346C3AA12; Mon, 23 Feb 2015 14:27:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=shiftleft.org; s=sldo; t=1424730456; bh=z/hYkPBVcBwQI14sSZ+89zRLX5zpEL2kpx/2X2Ucwds=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=INr1AMz9IlbHlqQnrRrLiqqLPDy1EegiONMrR5fQDkGvsnUO7jX1aGD4K/EG5iwjA PvZ/YmzNDejhEkk1ASJxi74271risrD7BtYMQn+MopN6kdcjqeUJdUFMenKgwnExC2 ijC4JQJk92cYcL+7XTTZt8zcInUgPk7JHleriaGw=
Content-Type: multipart/alternative; boundary="Apple-Mail=_19B7CCAD-F30F-42DB-80AB-B84EC9F229BC"
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2070.6\))
From: Michael Hamburg <mike@shiftleft.org>
In-Reply-To: <C6A08365-5C07-4874-97C6-DC99664C0E43@shiftleft.org>
Date: Mon, 23 Feb 2015 14:29:20 -0800
Message-Id: <AF0B8D18-ADE8-4F1E-AE51-D2BF52FB3EC6@shiftleft.org>
References: <54E46EA4.9010002@isode.com> <87bnkl7x0f.fsf@latte.josefsson.org> <CAMm+LwgWP8Hcbu1vSVUVH+80kJZ2OGKHU3qdrpZrp8NiJNX4rw@mail.gmail.com> <C6A08365-5C07-4874-97C6-DC99664C0E43@shiftleft.org>
To: Phillip Hallam-Baker <phill@hallambaker.com>
X-Mailer: Apple Mail (2.2070.6)
Archived-At: <http://mailarchive.ietf.org/arch/msg/cfrg/4FgYq7rSTZp3V_oFL5yBTuDtBkg>
Cc: Simon Josefsson <simon@josefsson.org>, "cfrg@irtf.org" <cfrg@irtf.org>
Subject: Re: [Cfrg] Elliptic Curves - poll on specific curve around 256bit work factor (ends on February 23rd)
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Feb 2015 22:29:23 -0000

> On Feb 23, 2015, at 2:26 PM, Michael Hamburg <mike@shiftleft.org> wrote:
> 
> I believe that the most recent discussion of the performance of strong curves is in this thread:
> 
> https://www.ietf.org/mail-archive/web/cfrg/current/msg05733.html <https://www.ietf.org/mail-archive/web/cfrg/current/msg05733.html>
Err, s/discussion/measurement/, since there is discussion in the more recent thread I cited below.

> This is for field arithmetic on Haswell, and there are several caveats mentioned in that thread.  Some approximation of relative performance of the whole curve (across implementation tradeoffs, Montgomery vs Edwards, comb size etc) can be obtained by multiplying the M and S times by the number of bits in the field.  See
> 
> http://www.ietf.org/mail-archive/web/cfrg/current/msg06084.html <http://www.ietf.org/mail-archive/web/cfrg/current/msg06084.html>
D’oh, — Mike