Hi Ron,

Here's a few references that discuss cofactors in signature verification:

https://ed25519.cr.yp.to/eddsa-20150704.pdf (cofactor = 2^c)
https://cr.yp.to/badbatch/badbatch-20120919.pdf

"Costs of cofactor > 1"
https://moderncrypto.org/mail-archive/curves/2014/

Trevor


On Tue, Nov 1, 2016 at 12:20 PM, Ron Garret <r...@flownet.com> wrote:
>
> So let me hard-fork this thread and ask a followup meta-question:  The fact 
> that 8 was the cofactor of the curve is apparently something most (if not 
> all) people on this list already knew.  But how?  Neither the Ed25519 paper 
> nor the Curve25519 paper mentions it (AFAICT).


Trevor
_______________________________________________
Curves mailing list
Curves@moderncrypto.org
https://moderncrypto.org/mailman/listinfo/curves

Reply via email to