[curves] Climbing the elliptic learning curve (was: Re: Finalizing XEdDSA)

Trevor Perrin trevp at trevp.net
Tue Nov 1 13:35:49 PDT 2016

Hi Ron,

Here's a few references that discuss cofactors in signature verification:

https://ed25519.cr.yp.to/eddsa-20150704.pdf (cofactor = 2^c)

"Costs of cofactor > 1"


On Tue, Nov 1, 2016 at 12:20 PM, Ron Garret <ron at flownet.com> wrote:
> So let me hard-fork this thread and ask a followup meta-question:  The fact that 8 was the cofactor of the curve is apparently something most (if not all) people on this list already knew.  But how?  Neither the Ed25519 paper nor the Curve25519 paper mentions it (AFAICT).


