From 83c3d976516b1070a12535fb1300fdaff41a343f Mon Sep 17 00:00:00 2001 From: Henry de Valence Date: Wed, 4 Apr 2018 11:29:36 -0700 Subject: [PATCH] clarify wording --- docs/ristretto-notes.md | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/docs/ristretto-notes.md b/docs/ristretto-notes.md index 7c80c25..b558b74 100644 --- a/docs/ristretto-notes.md +++ b/docs/ristretto-notes.md @@ -1,7 +1,7 @@ Below are some notes on Ristretto, which are not an authoritative writeup and which may have errors. See also the [Decaf paper][decaf_paper], the [libdecaf -implementation][ristretto_libdecaf], and the [Sage +implementation of Ristretto][ristretto_libdecaf], and its [Sage script][ristretto_sage]. Decaf constructs a prime-order group from a cofactor-\\(4\\) Edwards @@ -22,19 +22,17 @@ see the [Decaf paper][decaf_paper] or [_Jacobi Quartic Curves Revisited_][hwcd_jacobi] by Hisil, Wong, Carter, and Dawson). -When \\(e = a\^2\\), \\(\mathcal J\_{e,A}\\) has full +When \\(e = a\^2\\) is a square, \\(\mathcal J\_{e,A}\\) has full \\(2\\)-torsion (i.e., \\(\mathcal J[2] \cong \mathbb Z /2 \times \mathbb Z/2\\)), and we can write the \\(\mathcal J[2]\\)-coset of a point \\(P = (s,t)\\) as $$ P + \mathcal J[2] = \left\\{ - (s,t), (-s,-t), (1/as, -t/as\^2), (-1/as, t/as\^2) - \right\\}. $$ Notice that replacing \\(a\\) by \\(-a\\) just swaps the last two