5

For existing ECDH, I understand that there are recommended Elliptic Curve Domain Parameters. May I know if there are such similar considerations in SIDH? Any recommended Curve Domain Parameters?

yyyyyyy
  • 12,261
  • 4
  • 48
  • 68
Nathan Aw
  • 2,357
  • 3
  • 18
  • 22

1 Answers1

3

All 'good' implementations so far have used the same curve, but there is now variation in the underlying finite field, which affects the other base parameters of the public points for each party and the range of values for the secret scalars. The best reference as yyyyyyy mentioned is the NIST PQC submission for SIKE, which includes valid options for SIDH with some extra protocol stuff on top. The parameter sets in there are p503, p751 (the most studied one) and p964.