[Cryptech Tech] Storage of curve parameters for ECDSA

Rob Austein sra at hactrn.net
Thu Jan 14 19:42:27 UTC 2016


At Thu, 14 Jan 2016 20:38:24 +0100, Peter Stuge wrote:
> 
> Pavel Shatov wrote:
> > Since I'm trying to write ECDSA core, not general-purpose EC math core,
> > I thought, that it would make sense to take advantage of the fact and
> > get rid of that redundant coefficient.
> 
> Is there a security concern with such an optimization - side-channel
> or otherwise?

I don't think so.  The curve parameters are public information.


More information about the Tech mailing list