International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 07 July 2014

Daniel J. Bernstein, Chitchanok Chuengsatiansup, Tanja Lange
ePrint Report ePrint Report
This paper introduces constant-time ARM Cortex-A8 ECDH software that

(1) is faster than the fastest ECDH option in the latest version of OpenSSL but

(2) achieves a security level above 2^200 using a prime above 2^400.

For comparison, this OpenSSL ECDH option is not constant-time and has a security level of only 2^80.

The new speeds are achieved in a quite different way

from typical prime-field ECC software:

they rely on a synergy between Karatsuba\'s method

and choices of radix smaller than the CPU word size.

Expand

Additional news items may be found on the IACR news page.