The authors want to thank Feico Dillema, Jaap-Henk Hoepman, Åge Kvalnes, Sape Mullender, Per Harald Myrvang, and the anonymous referees for valuable comments. The first author also wants to thank George Barwood and Paulo Barreto for providing source code and useful information on how to implement elliptic curve cryptography.