Re: [Cfrg] A draft merging rpgecc and thecurve25519function.

Watson Ladd <> Fri, 02 January 2015 00:08 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 8C5821A802A for <>; Thu, 1 Jan 2015 16:08:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id dEKNBf-r-rBl for <>; Thu, 1 Jan 2015 16:08:09 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4002:c07::22c]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 842431A1B11 for <>; Thu, 1 Jan 2015 16:08:09 -0800 (PST)
Received: by with SMTP id 131so8502159ykp.17 for <>; Thu, 01 Jan 2015 16:08:08 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=IHQxPyYKqSo2Ma223zUC1ekzBeiAxecwU9BRLR8uDhU=; b=HZQX0egOhntZcvTLPsqTw5WelU0LGDluo2IaW1xRXmmcRK4cKqlYcCcXxYYH/OW+Zd jZLWjujhzoU3TVA4LO3BLrTCpSeH/nLdmWjDOGPPm73XD/J3xE3stBMx0Sm713rb0mNX 5MbvzTSL/393kjx6lsRMykfg2IPlYKT6rFd7+f5S77Gab53l71UGCaxhI/qooqlu/tii lPUp1W62baUGgEtFN19UVncgWuQf9OQoCRu1OvFwRVpX0khtqyR/eYhUMGntv0OhytE9 C7Gl+OXXHR73YltxxjmdlLosxVmihidcbvb58UBipyy4l+AD0XFyUSxavWv7rVBTdUyo rmFw==
MIME-Version: 1.0
X-Received: by with SMTP id h38mr5640742yhq.172.1420157288657; Thu, 01 Jan 2015 16:08:08 -0800 (PST)
Received: by with HTTP; Thu, 1 Jan 2015 16:08:08 -0800 (PST)
In-Reply-To: <>
References: <> <>
Date: Thu, 1 Jan 2015 19:08:08 -0500
Message-ID: <>
From: Watson Ladd <>
To: Adam Langley <>
Content-Type: text/plain; charset=UTF-8
Cc: "" <>
Subject: Re: [Cfrg] A draft merging rpgecc and thecurve25519function.
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 02 Jan 2015 00:08:11 -0000

On Thu, Jan 1, 2015 at 6:31 PM, Adam Langley <> wrote:
> On Thu, Jan 1, 2015 at 2:00 PM, Adam Langley <> wrote:
>> The resulting agglomeration is at
>> (requires
>> XSLT support in the browser)
> Tanja points out that that I had 2^255-19 as 3 mod 4. Getting rawgit
> to serve XSLT and sorting out the caching is a real pain, so forget
> that link and use
> instead. (Still
> uses XSLT support in the browser.)

Is it just me, or is this the draft I uploaded a couple weeks ago,
plus typos, and a section about an algorithm that gets used only to
have its result ignored? Should cat be a coauthor?

This is especially true when discussing the Edwards form at all, given
that we are talking about ECDH with the equivalent Montgomery form. If
we're going to use the NUMS generation algorithm (and we might as
well: it's what we've been doing all along now) over other primes,
then we should discuss the relation between the Edwards form and
Montgomery form, as otherwise the reader has no idea where the magic
numbers are coming from, or even why we are discussing Edwards form,
given that the presented algorithms don't use it.

I can't speak for my coauthors, but the above issues seem surmountable
with a bit of editing, and would give us a document that's easy to
extend when we select the higher strength prime.


> Cheers
> --
> Adam Langley
> _______________________________________________
> Cfrg mailing list

"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin