[BLS-wg] Reverse BLS12-381
Bram Cohen
bram at chia.net
Sat Mar 17 01:12:59 EDT 2018
On Fri, Mar 16, 2018 at 6:25 PM, Sean Bowe <sean at z.cash> wrote:
> > Right, we're swapping the curves from *a* implementation which was used
> to give reference numbers but not actually misusing the primitive at all.
>
> I think it's totally fine if you want to use G1 for public keys, but
> I'm still confused about the language you're using to describe
> BLS12-381.
>
All confusion is strictly mine! Since I'm not the one doing the
implementing I'm being a bit sloppy with BLS the algorithm, BLS12-381 the
curve, and whatever we're supposed to call a specific implementation of
that, which apparently doesn't have standards or names so far.
In any case, I called it 'reverse' because at least one thing I looked at
said that if you use BLS12-381 then the sizes of keys will be 96 bytes,
hence the interpretation of that as the 'normal' thing to do and what we're
doing as 'reverse'.
More information about the bls-wg
mailing list