[curves] Climbing the elliptic learning curve (was: Re: Finalizing XEdDSA)

Trevor Perrin trevp at trevp.net
Tue Nov 1 13:35:49 PDT 2016


Hi Ron,

Here's a few references that discuss cofactors in signature verification:

https://ed25519.cr.yp.to/eddsa-20150704.pdf (cofactor = 2^c)
https://cr.yp.to/badbatch/badbatch-20120919.pdf

"Costs of cofactor > 1"
https://moderncrypto.org/mail-archive/curves/2014/

Trevor


On Tue, Nov 1, 2016 at 12:20 PM, Ron Garret <ron at flownet.com> wrote:
>
> So let me hard-fork this thread and ask a followup meta-question:  The fact that 8 was the cofactor of the curve is apparently something most (if not all) people on this list already knew.  But how?  Neither the Ed25519 paper nor the Curve25519 paper mentions it (AFAICT).


Trevor


More information about the Curves mailing list