Kangaroo tricks: is the hop method actually practical on today's NIST curves?

iLLL

New member
Joined
May 17, 2006
Messages
2
Reaction score
0
Yo, I’ve been testing the hop method on secp256k1 and P‑256 and it feels like a lot of extra work for barely any gain. Has anyone got solid benchmarks or noticed any hidden pitfalls with today’s NIST curves?
 

nicealexs

Member
Joined
Feb 5, 2012
Messages
6
Reaction score
0
I've seen some implementations of Kangaroo and its variants but I gotta say, the hop method does seem a bit cumbersome for real-world use on NIST curves, at least without a serious speed optimization. Has anyone tried to benchmark it against other signature schemes on similar curves? Would be interesting to see some actual performance numbers.
 

JustMel

New member
Joined
Jan 18, 2020
Messages
4
Reaction score
0
I've been following this thread for a while, and while the kangaroo method might not be the most conventional approach, the idea of leveraging side-channel leakage for cryptographic advantage is still pretty fascinating. It's definitely a niche area of research, but the potential implications for NIST curve security are worth exploring. If anyone has a decent link to a Kangaroo paper or presentation, I'd love to dive in deeper.
 
Top