[Cryptography] Why is ECC secure?

Viktor Dukhovni cryptography at dukhovni.org
Thu Aug 13 19:26:23 EDT 2015


On Wed, Aug 12, 2015 at 06:12:13PM -0700, Bill Cox wrote:

> I used Wolfram to evaluate the path integral for several multiples of the
> generator point, and indeed, they are clearly multiples of a constant.

An Edwards curve over the reals is a compact subset of R^2 bounded
away from (0,0).  Therefore, your scaled metric gives the image of
the curve on S^2 a finite diameter, but there are points of infinite
order on the curve when the generator "G" is not a torsion element.

Therefore, any proportionality between "n" and the "distance" of
"nG" from some reference point (pick any continuous metric), fails
for large enough "n".  Thus, before we even consider whether any
of this applies to the discrete case, it seems clear that this must
fail in the continuous case.

-- 
	Viktor.


More information about the cryptography mailing list