[cryptography] Point compression prior art?

Paul Crowley paul at ciphergoth.org
Fri May 20 18:40:25 EDT 2011


On 20/05/11 23:14, Zooko O'Whielacronx wrote:
> How about the "Compact Representation", section 4.2, of RFC 6090:
>
> http://www.rfc-editor.org/rfc/rfc6090.txt
>
> Is that the same "point compression" that you were looking for?

Sadly not; this is the "discard y, transmit only x" scheme described in 
the original CRYPTO 85 paper introducing elliptic curve cryptography. 
This  works for ECDH, but for protocols such as ECDSA it's harder to see 
how to make do with only one of the coordinates.  Thanks for the 
reference though!
-- 
   __
\/ o\ Paul Crowley, paul at ciphergoth.org
/\__/ http://www.ciphergoth.org/



More information about the cryptography mailing list