'80 - Introduction

Weierstrass curve

The formulas used for this curves are derived from the work done by the Chudnovsky brothers and as we will see shortly might not be the most efficient. The complete formulas are somehow complicated and on top is not easy to implement constant time algorithm for those curves (unless replace all that code with curve specific, constant-time code). This paper from Brown,Hankerson, Lopez, Menezes shows several optimizations that can be done for NIST's elliptic curves.

One important thing to remember for the sake of this blog post is that this kind of curves have a minimum cofactor of 1, hence the might have a prime order (like all the NIST curves).

Now I am not saying this is the end of Curve25519 and/or Montgomery Curve BUT lately the great Weierstrass curve. and/orBUT lately the great Prof. Barreto proposed a new curve that is prime order and a

Weierstrass curves? Aka ending as we started with Vico This made me thinking, is Prof. Barreto right? Should we go back to

Historical courses and resorts in Elliptic Curves Cryptography That's all folks. For more crypto goodies, follow me on Twitter

tl;dr This short blog post serves to me to recollect some of the thing I have been learning ( climbing ) about Elliptic Curves Cryptography (ECC from now on) during the last months/years, so please take it with a grain of salt since it might contains some erroneous beliefs.