Youssef El Housni
Youssef El Housni
The primary goal to have a twisted Edwards is to use the law completeness to implement windowed scalar multiplication inside a circuit. If you convert BLS12-377 to a twisted Edwards...
> The primary goal to have a twisted Edwards is to use the law completeness to implement windowed scalar multiplication inside a circuit. If you convert BLS12-377 to a twisted...
The security of BLS12-377 wrt STNFS and Cheon's attack is discussed in section 4 [here](https://eprint.iacr.org/2020/351.pdf).
Yes because the analysis takes Cheon's attack into consideration as opposed to [Guillevic19].
> @yelhousni is the paper author. Thank you for tagging me. This is a joint work with @auroreguillevic.
It is indeed incomplete but "practically" complete with a reasonable assumption. The points at infinity are all of even order while we work on a field of odd prime order....