[Cfrg] Fwd: 25519 naming

David Leon Gil <coruus@gmail.com> Wed, 27 August 2014 18:15 UTC

Return-Path: <coruus@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com []) by ietfa.amsl.com (Postfix) with ESMTP id 49EEF1A6EE6 for <cfrg@ietfa.amsl.com>; Wed, 27 Aug 2014 11:15:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([]) by localhost (ietfa.amsl.com []) (amavisd-new, port 10024) with ESMTP id q8VVqtLcUAwX for <cfrg@ietfa.amsl.com>; Wed, 27 Aug 2014 11:15:55 -0700 (PDT)
Received: from mail-la0-x231.google.com (mail-la0-x231.google.com [IPv6:2a00:1450:4010:c03::231]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 082AC1A212A for <cfrg@irtf.org>; Wed, 27 Aug 2014 11:15:54 -0700 (PDT)
Received: by mail-la0-f49.google.com with SMTP id pv20so377204lab.36 for <cfrg@irtf.org>; Wed, 27 Aug 2014 11:15:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type; bh=R3ttSqiS0VZYLygQVfqogU8kQ2o2mgno2qdIx1pHKAM=; b=pOWaMGUuiKHdMH62Nm0vmu+wReGtvpHTe+2r4B8cmSxFJQsjy7sSiVBlpcSfSwg1u2 FIw3Eb2akNpgWUw7FXLT+OVzpVrD63LU6ELv6A4dDL/6Ldi1aZR74UEHFFMvGNT8P+92 Iqi6vWxpEudCJej9EHEDSwpFSrF6pTrdOC6siM3ulDM0qF/mTxgFLfiEgS1cDQSPLRJN BUSdqxuPrI1W3BvHePh0MVt9tGEizGLHvWQ8225UCaB1aD4NAANHAJPvtMYoYTFiSWBC sqAG2yiyTThDS8HqmmuUps+BDxTKJGkuwqThFX89qpMoASYbix8vcu7eJBM+UBZJS8J7 0c2Q==
X-Received: by with SMTP id w15mr22149795lbi.84.1409163353067; Wed, 27 Aug 2014 11:15:53 -0700 (PDT)
MIME-Version: 1.0
Received: by with HTTP; Wed, 27 Aug 2014 11:15:33 -0700 (PDT)
In-Reply-To: <CAA7UWsWV2VE30k-z_=exWHEgWijn-eHYTpg8pBQfnqEzTu6SAg@mail.gmail.com>
References: <20140825234305.7799.qmail@cr.yp.to> <CAA7UWsUHLdXRg0-hpFZBAGUTrexU=CzOBcw+DqFey48MdCboLg@mail.gmail.com> <CACsn0c=6hv8u08OtEZMuD=pDTcw+xgvSJ0z2viaWX3ynASRMWQ@mail.gmail.com> <CAA7UWsWV2VE30k-z_=exWHEgWijn-eHYTpg8pBQfnqEzTu6SAg@mail.gmail.com>
From: David Leon Gil <coruus@gmail.com>
Date: Wed, 27 Aug 2014 14:15:33 -0400
Message-ID: <CAA7UWsUS1vGXwuQtfvgk3qVYpzEQVqQCFYEkoyRO4m4Sk2sN-A@mail.gmail.com>
To: "cfrg@irtf.org" <cfrg@irtf.org>
Content-Type: multipart/alternative; boundary=14dae93d94ce1714bc0501a06927
Archived-At: http://mailarchive.ietf.org/arch/msg/cfrg/BSLb_4Mc3ht32x4NkMwjn6JTCGc
Subject: [Cfrg] Fwd: 25519 naming
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Aug 2014 18:15:57 -0000

(Yes; I significantly misspoke in my first paragraph: indeed,
different geometries. The perils of curves before coffee.)

On Wednesday, August 27, 2014, Watson Ladd <watsonbladd@gmail.com>; wrote:
>  To avoid all this verbiage, which everyone understands (with the usual
> criteria about what "everyone" means) we speak in the informal language of
> coordinates, and then mentally translate into the language of EGA. I don't
> see what's missing from DJBs email in this regard.
'Everyone', for our purposes, should be the 'everyone' who reads RFCs.

These two things are quite different:

- Changing coördinates on the *same* curve (e.g., Jacobian to affine).
- Transferring points to another equivalent curve (e.g., Montgomery to

My posit is that eliding this difference is (a small part of) the *cause*
of the confusion djb notes.

It is easy enough to be explicit about the latter. E.g., from the Ed25519
paper (line breaks inserted):

- Curve25519 ... is the Montgomery curve v^2 = u^3 + 486662 u^2 + u over
- [...] Curve25519 is birationally equivalent to an Edwards curve,
specifically x^2 + y^2 = 1 + (121665/121666) x^2 y^2; the equivalence is x
= √486664 u / v and y = (u − 1)/(u + 1).
- [T]his Edwards curve is isomorphic to −x^2 + y^2 = 1 − (121665/121666)
x^2 y^2 . . . .

I'd suggest that talking in this way is better than talking about different
curves as 'coordinate systems'.