[Cryptography] Time for djb's Edwards curves in TLS?

Viktor Dukhovni cryptography at dukhovni.org
Tue Sep 10 12:15:38 EDT 2013

Is there a TLS WG draft adding djb's Curve1174 to the list of named
curves supported by TLS?  If there's credible doubt about the safety
of the NIST curves, it seems that Curve1174 (in Edwards form) would
make a good choice for EECDH, perhaps coupled with a similar curve
with ~512 bits.

Slides with rationale:


Detailed paper motivating Curve1174:


The current situation with EECDH over the NIST prime curves not
shown compromised, but no longer trusted is rather sub-optimal.


