On Wed, Mar 29, 2017 at 12:34 PM, Ron Garret <r...@flownet.com> wrote:
> What would be the benefit? > The main benefit is that the D-H use case deals only with Montgomery-x coordinates, and all scalar multiplications can be performed using the Montgomery ladder. > It seems to me that it doesn’t really matter much one way or the other, > but if you’re going to convert one to the other then it seems to make more > sense to derive the DH key from the DSA key because going the other way you > lose the sign of the Y coordinate. > Trevor wrote a great post highlighting the respective tradeoffs here: https://moderncrypto.org/mail-archive/curves/2015/000376.html -- Tony Arcieri
_______________________________________________ Curves mailing list Curves@moderncrypto.org https://moderncrypto.org/mailman/listinfo/curves