Hi Ron, Here's a few references that discuss cofactors in signature verification:
https://ed25519.cr.yp.to/eddsa-20150704.pdf (cofactor = 2^c) https://cr.yp.to/badbatch/badbatch-20120919.pdf "Costs of cofactor > 1" https://moderncrypto.org/mail-archive/curves/2014/ Trevor On Tue, Nov 1, 2016 at 12:20 PM, Ron Garret <r...@flownet.com> wrote: > > So let me hard-fork this thread and ask a followup meta-question: The fact > that 8 was the cofactor of the curve is apparently something most (if not > all) people on this list already knew. But how? Neither the Ed25519 paper > nor the Curve25519 paper mentions it (AFAICT). Trevor _______________________________________________ Curves mailing list Curves@moderncrypto.org https://moderncrypto.org/mailman/listinfo/curves