[Cryptography] Seed values for NIST curves

Tony Arcieri bascule at gmail.com
Tue Sep 10 13:42:56 EDT 2013


On Tue, Sep 10, 2013 at 3:36 AM, Joachim Strömbergson <
Joachim at strombergson.com> wrote:

> 1. We as a community create a list of curves that we agree on are good.
> The list is placed in a document, for example an RFC that clearly states
> what criteria has been used, what the sources for the curves are and how
> they has been generated. This allows any user to check the validity and
> the provenance.


This is more or less what djb did, sans the politics of an Internet
standards process (others have written IETF-style guidelines for actually
deploying his ciphers)

djb's rationale for Curve25519's parameters are provided in the paper. The
2^255-19 constant was selected by a theorem (see Theorem 2.1):

http://cr.yp.to/ecdh/curve25519-20060209.pdf

-- 
Tony Arcieri
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://www.metzdowd.com/pipermail/cryptography/attachments/20130910/d3a5bcff/attachment.html>


More information about the cryptography mailing list