Re: [Cfrg] Complexity of the Microsoft curve proposal

Benjamin Black <b@b3k.us> Fri, 17 October 2014 23:55 UTC

Return-Path: <b@b3k.us>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B10601A87C9 for <cfrg@ietfa.amsl.com>; Fri, 17 Oct 2014 16:55:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.503
X-Spam-Level:
X-Spam-Status: No, score=-1.503 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, BIGNUM_EMAILS=0.474, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p-zbbBjto7Ee for <cfrg@ietfa.amsl.com>; Fri, 17 Oct 2014 16:55:04 -0700 (PDT)
Received: from mail-wg0-f51.google.com (mail-wg0-f51.google.com [74.125.82.51]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C26B91A87C7 for <cfrg@ietf.org>; Fri, 17 Oct 2014 16:55:03 -0700 (PDT)
Received: by mail-wg0-f51.google.com with SMTP id b13so1884815wgh.34 for <cfrg@ietf.org>; Fri, 17 Oct 2014 16:55:02 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=nf3pgCtkOdDJclX797lNwv3pWUkMugXv7Yr5aSejY8g=; b=RF5chAfHwIqupfsyfFnInBH04ZSDDVNAWxTmHqh6PmBplmThuZ9P0gJxiV9XUWPTu3 4pJVx0ksrakU2+73yGndzCvba4CDtKoS7FbvWDpY/N17cy4qTIl4PG7EpbVdEEHxqDKU USatfxkmYyO7nM9H/1/9oXaviOqF/v70QOe8rMNxvz2WPOHrjgsuR34aWmeapV3r+AUm 2+uWQr/HsiWRUyNLfuvjpqiPYYDNGzO9a3BAe4U+jRt4W3+o8woFP7xKSqvuhBHeabR2 B4mnJkGpBbyN3cO9dNl0IWxxDnIWiVu3ABS41WvMP9oU/HZXV/TzBNRuKjhk49pxGU/r LWsA==
X-Gm-Message-State: ALoCoQmOyu6Fc62pZP1Cme1LbdXQXKpKr53KXNncdUvDNpJ0ZlfRJU2SkW6ksCAHmf71sgtXyL7W
X-Received: by 10.180.149.169 with SMTP id ub9mr2247214wib.73.1413590102334; Fri, 17 Oct 2014 16:55:02 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.217.14.70 with HTTP; Fri, 17 Oct 2014 16:54:42 -0700 (PDT)
In-Reply-To: <253D0648-0DDE-497E-8BC1-4DD2805640E4@shiftleft.org>
References: <075fdb98d04b42d08e39dbc706cc21fa@DM2PR03MB495.namprd03.prod.outlook.com> <253D0648-0DDE-497E-8BC1-4DD2805640E4@shiftleft.org>
From: Benjamin Black <b@b3k.us>
Date: Fri, 17 Oct 2014 16:54:42 -0700
Message-ID: <CA+Vbu7wBH2LfAiCcTUOkSn=bSzMoq2Zehz2YxfzA0hCeFgteyA@mail.gmail.com>
To: Michael Hamburg <mike@shiftleft.org>
Content-Type: multipart/alternative; boundary="001a11c38aeae891560505a717d5"
Archived-At: http://mailarchive.ietf.org/arch/msg/cfrg/RU8Q2gXkBcrXOZe2MKloirP-tIE
Cc: "cfrg@ietf.org" <cfrg@ietf.org>, Craig Costello <craigco@microsoft.com>
Subject: Re: [Cfrg] Complexity of the Microsoft curve proposal
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Oct 2014 23:55:06 -0000

On Tue, Oct 14, 2014 at 6:03 PM, Michael Hamburg <mike@shiftleft.org> wrote:

> I don’t think everyone on this list would agree with the above statement,
> though.  A pretty big part of Benjamin Black’s argument against \w+25519 is
> the idea that they are different curves, not just different coordinates for
> the same curve, even though the curves are isomorphic and not just
> isogenous.
>
>
For the record, my argument was, and is, that _requiring_ implementation of
multiple forms of the same curve is undesirable and unnecessary. At the
time, the discussion was not \w+25519, but X25519 and Ed25519 (and
apologies if I have made mistakes with the various 25519 names). As the
discussion has moved on from there, I don't think it is terribly relevant.


b