ECC point compression trick



Think about what mm said ... why can't we just always use one of the
roots?

e.g. you have

y == +/- sqrt(x^3 - 3x + b)

Why not always just use the positive root [adjusting your secret
multiplier as required since (-k)P == k(-P)].

You still have to compute the root to find y but now you don't even
send the one bit. You just send x.

This halves the key space but I don't see how that causes any practical
problems. You're still going to have to cycle find it.

Tom

.