ECDSA for Edwards curve

Werner Koch wk at gnupg.org
Mon Oct 21 17:34:40 CEST 2013


On Mon, 21 Oct 2013 12:43, wk at gnupg.org said:

> Or forget about Ed25519 and use P-256 directly?  Needs to be discussed
> with the GNUnet folks.

There is an easier way to do that.  We only have 255 bit thus the there
is one spare bit to represent the sign.  This is similar to what EdDSA
does, pretty easy and sufficient for the GNUNET case.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.




More information about the Gcrypt-devel mailing list