why did Ed25519 used Edward25519 instead of Curve25519 directly?
You’re referring to a specific algorithm (Montgomery ladder) for a specific operation (X25519). Regarding the curve itself, point addition is not a problem if you have both coordinates.
-
-
Is Curve25519 point addition constant-time and exception-free though? ISTR it has to treat the two points being equal as a special case.
-
Not something we usually care about for Schnorr signature verification.
- 3 more replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.