Cryptology ePrint Archive: Report 2015/677

EdDSA for more curves

Daniel J. Bernstein and Simon Josefsson and Tanja Lange and Peter Schwabe and Bo-Yin Yang

Abstract: The original specification of EdDSA was suitable only for finite fields Fq with q mod 4 = 1. The main purpose of this document is to extend EdDSA to allow finite fields Fq with any odd q. This document also extends EdDSA to support prehashing, i.e., signing the hash of a message.

Category / Keywords: public-key cryptography / Signatures, elliptic curves, Edwards curves, Ed25519, Curve41417, Ed448-Goldilocks,, Ed521

Date: received 5 Jul 2015

Contact author: tanja at hyperelliptic org

Version: 20150705:180811 (All versions of this report)

