> Thanks for this pointer. Are you still working in this area? Do you think
> further big improvements in explicit formulas are likely?
> I'm wondering if I should pick a fast curve form now to include in Crypto++, or wait until
> things settle down a bit more.
Yes, I am still working on the topic.
I believe that there will be many more improvements in the future. I
hope, it never settles down ;=).
We have a new ACISP09 paper coming up for Jacobi quartics.
I have implemented both curves in Diffie-Hellman key exchange with
latest formulas, assembly optimizations, and lookup tables.
Twisted Edwards (a=-1) seems to be superior in performance.
> Has anyone tried to estimate a lower bound on the number of field operations
> needed for a curve scalar multiplication?
I do not know any results on this.