Re: [Cfrg] New names for draft-ladd-safecurves

Robert Ransom <rransom.8774@gmail.com> Tue, 21 January 2014 05:11 UTC

Return-Path: <rransom.8774@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E65C1A0048 for <cfrg@ietfa.amsl.com>; Mon, 20 Jan 2014 21:11:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.75
X-Spam-Level:
X-Spam-Status: No, score=-1.75 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wRdGzWAR0pvI for <cfrg@ietfa.amsl.com>; Mon, 20 Jan 2014 21:11:54 -0800 (PST)
Received: from mail-qe0-x230.google.com (mail-qe0-x230.google.com [IPv6:2607:f8b0:400d:c02::230]) by ietfa.amsl.com (Postfix) with ESMTP id 302191A0036 for <cfrg@irtf.org>; Mon, 20 Jan 2014 21:11:54 -0800 (PST)
Received: by mail-qe0-f48.google.com with SMTP id b4so2070767qen.21 for <cfrg@irtf.org>; Mon, 20 Jan 2014 21:11:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=K5WxuUWbjWddHpGEMPPLtSMcRXcPa5HDqw9SBK5SjvU=; b=wCBtzaxj9Omvn6cP2hyFjf9kgvI5AlzZQIIJZctNsKIUCLyZaRGFhuMyMEJoeSDzmk 6/ucIGasoLSaI7yddSah1PHvzWGHAXVX6Zg1Na7eg68adSJgRMaOC3S4M3hx2yETFohL ztrSJHiMoKySoy1zBL99aT5RFOVdj4xUasj6Ga2JIUmzsxw18xcNM+U9WFUXqpn199s9 ia2sJf9ypX3Nnpy1yC3aw8R9cDSH6KLDiYAbp8NnLUTEZUvwQvnK9FywTeeVbvHyCNgu 5wgEoFBPXO/o0FllyiFunWt5GF0pmc5w0lm2q0Q/aJuje5meWnsx8Eefjts5Kmy6ve3A Qg/Q==
MIME-Version: 1.0
X-Received: by 10.224.53.71 with SMTP id l7mr34045808qag.33.1390281114020; Mon, 20 Jan 2014 21:11:54 -0800 (PST)
Received: by 10.229.181.132 with HTTP; Mon, 20 Jan 2014 21:11:53 -0800 (PST)
In-Reply-To: <CABqy+srh=n0dhfnmyFs9+cwYNcZNVEe1cLtous0Z2NBiuS=gmw@mail.gmail.com>
References: <CACsn0ck02mnETBUfuyJjLV9K8Yuiki8_-RG0tVszL8BDhkK27w@mail.gmail.com> <6489F7D3-BF54-416F-94BE-64FD1CFCCB1E@callas.org> <CACsn0cn0938BHMs7uFJYeB_q2VcGQULcF8fzc7KR67A_+mqzLw@mail.gmail.com> <264676DC-14DA-432E-81AB-CD0D852307A4@shiftleft.org> <CABqy+sr1zc-T-F3D_VOoz2B9GNZPsAxi=HeMoe=DwG5EJq8AuA@mail.gmail.com> <972ED43E-96A5-4B4B-A117-3DC88D00B778@shiftleft.org> <CABqy+srh=n0dhfnmyFs9+cwYNcZNVEe1cLtous0Z2NBiuS=gmw@mail.gmail.com>
Date: Mon, 20 Jan 2014 21:11:53 -0800
Message-ID: <CABqy+sr5jsex5fypHQ+HoYMQobRAvjtcwzWzWNgbAJjFP-K87A@mail.gmail.com>
From: Robert Ransom <rransom.8774@gmail.com>
To: Mike Hamburg <mike@shiftleft.org>
Content-Type: text/plain; charset=UTF-8
Cc: "cfrg@irtf.org" <cfrg@irtf.org>, Jon Callas <jon@callas.org>
Subject: Re: [Cfrg] New names for draft-ladd-safecurves
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Jan 2014 05:11:55 -0000

On 1/20/14, Robert Ransom <rransom.8774@gmail.com> wrote:
> On 1/20/14, Mike Hamburg <mike@shiftleft.org> wrote:
>> On Jan 20, 2014, at 8:25 PM, Robert Ransom <rransom.8774@gmail.com>
>> wrote:
>
>>> The Montgomery-form ladder is as efficient for small-integer
>>> Edwards-form d as it is for small-integer Montgomery-form parameter
>>> ((A-2)/4 or (A+2)/4).
>
>> So it is.  Do you have a reference for that, BTW?
>
> I don't have a reference for it.  (But I did use it in my Curve1174
> implementation last summer, and I'm pretty sure I said it a few days
> ago on this list.)
>
> <http://hyperelliptic.org/EFD/g1p/data/twisted/coordinates> gives an
> isomorphism to Montgomery form with A = 4a/(a-d) - 2; the parameter
> for the formulas given on
> <http://hyperelliptic.org/EFD/g1p/auto-montgom-xz.html> is a24 =
> (A+2)/4 = a/(a-d).  So the fact that when d is a small integer (and a
> is 1 or -1, as usual), the Montgomery-form parameter is the reciprocal
> of a small integer is fairly obvious from that.
>
> The remaining step is to move the multiplication by 1/a24 into BB.

Er.  Move the multiplication by 1/a24 into BB *after* BB is used in
calculating E.


Robert Ransom