RFC 9496
The ristretto255 and decaf448 Groups, December 2023
- File formats:
- Also available: XML file for editing
- Status:
- INFORMATIONAL
- Authors:
- H. de Valence
J. Grigg
M. Hamburg
I. Lovecruft
G. Tankersley
F. Valsorda - Stream:
- IRTF
Cite this RFC: TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC9496
Discuss this RFC: Send questions or comments to the mailing list cfrg@irtf.org
Other actions: Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 9496
Abstract
This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448.
This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.
For the definition of Status, see RFC 2026.
For the definition of Stream, see RFC 8729.