ECDSA for Edwards curve

Werner Koch wk at
Mon Oct 21 17:34:40 CEST 2013

On Mon, 21 Oct 2013 12:43, wk at said:

> Or forget about Ed25519 and use P-256 directly?  Needs to be discussed
> with the GNUnet folks.

There is an easier way to do that.  We only have 255 bit thus the there
is one spare bit to represent the sign.  This is similar to what EdDSA
does, pretty easy and sufficient for the GNUNET case.



Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.

More information about the Gcrypt-devel mailing list