Meta tags:
Headings (most frequently used words):
curve25519, contents, mathematical, properties, history, libraries, protocols, applications, notes, references, external, links,
Text of the page (most frequently used words):
the (65), retrieved (43), and (25), #curve25519 (24), for (21), cryptography (20), curve (17), 2016 (16), 2014 (16), elliptic (13), key (13), from (12), edit (12), 2017 (12), security (12), 2015 (12), bernstein (11), protocol (10), original (10), 2018 (10), ed25519 (9), pdf (9), 2019 (9), archived (9), that (9), rfc (9), was (8), with (8), encryption (8), daniel (8), wikipedia (7), org (7), december (7), github (7), notes (7), doi (7), used (7), this (6), use (6), name (6), curves (6), based (6), nsa (6), hellman (6), public (6), has (6), version (6), tls (6), 2013 (6), using (5), page (5), september (5), signature (5), function (5), x25519 (5), openssh (5), openssl (5), openbsd (5), ssh (5), crypto (5), com (5), exchange (5), new (5), algorithm (5), 186 (5), safecurves (5), lange (5), tanja (5), high (5), prime (5), since (5), contents (4), search (4), ed448 (4), ecdh (4), links (4), tor (4), april (4), support (4), release (4), omemo (4), implementation (4), introduction (4), file (4), 17487 (4), ietf (4), internet (4), nist (4), february (4), libssh (4), speed (4), signatures (4), diffie (4), only (4), history (4), subgroup (4), hide (4), move (4), sidebar (4), view (3), privacy (3), may (3), cs1 (3), web (3), discrete (3), logarithm (3), scheme (3), algorithms (3), viber (3), blog (3), log (3), mail (3), peerio (3), end (3), murenin (3), constantine (3), slashdot (3), reference (3), src (3), released (3), not (3), gnunet (3), changes (3), specification (3), bitchat (3), october (3), conversations (3), 2021 (3), libsodium (3), botan (3), wolfssl (3), library (3), cite (3), mbed (3), polarssl (3), transport (3), layer (3), numbers (3), domain (3), dnssec (3), draft (3), fips (3), national (3), institute (3), standards (3), technology (3), 7748 (3), 2020 (3), secure (3), shell (3), gnupg (3), schneier (3), breaking (3), 800 (3), 978 (3), 540 (3), coordinates (3), montgomery (3), order (3), via (3), signal (3), applications (3), special (3), 256 (3), point (3), displaystyle (3), tools (3), main (3), add (2), languages (2), toggle (2), table (2), contact (2), about (2), policy (2), terms (2), non (2), foundation (2), inc (2), last (2), generic (2), maint (2), deprecated (2), archival (2), service (2), short (2), description (2), wikidata (2), post (2), quantum (2), size (2), trust (2), digital (2), rsa (2), naccache (2), stern (2), rlwe (2), kex (2), x448 (2), goldwasser (2), external (2), whatsapp (2), threema (2), whitepaper (2), sqrl (2), www (2), putty (2), proton (2), faster (2), soulskill (2), longer (2), packages (2), monero (2), apple (2), march (2), gajim (2), plugin (2), dropbear (2), frank (2), denis (2), dnscrypt (2), cryptocat (2), 2025 (2), group (2), nss (2), schannel (2), august (2), help (2), comparison (2), libgcrypt (2), 8446 (2), john (2), cryptographic (2), method (2), dkim (2), 2024 (2), adamantiadis (2), curve448 (2), what (2), most (2), talk (2), approved (2), many (2), dual_ec_drbg (2), 2007 (2), advances (2), cryptology (2), asiacrypt (2), lecture (2), computer (2), science (2), vol (2), springer (2), isbn (2), 1007 (2), duif (2), niels (2), schwabe (2), peter (2), yang (2), yin (2), efd (2), 2006 (2), efficient (2), pseudo (2), mersenne (2), 25519 (2), link (2), 2023 (2), patents (2), references (2), when (2), starting (2), windows (2), wireguard (2), messenger (2), proposed (2), protocols (2), libraries (2), allow (2), published (2), publication (2), both (2), described (2), usage (2), allows (2), constants (2), them (2), had (2), implemented (2), related (2), first (2), uses (2), defined (2), number (2), 252 (2), 27742317777372353535851937790883648493 (2), 255 (2), mathematical (2), properties (2), ecc (2), appearance (2), upload (2), read (2), article (2), create (2), account (2), donate (2), menu (2), topic, mobile, cookie, statement, statistics, developers, code, conduct, legal, safety, contacts, disclaimers, text, available, under, additional, apply, site, you, agree, registered, trademark, profit, organization, wikimedia, creative, commons, attribution, sharealike, license, rendered, parsoid, edited, 2026, utc, hidden, categories, errors, matches, articles, category, https, index, php, title, oldid, 1374209302, openpgp, card, identity, pki, fingerprint, oaep, topics, cnsa, suite, nessie, ieee, p1363, cryptrec, standardization, tropical, trapdoor, problem, commutative, hash, theory, sphincs, sqisign, xtr, three, pass, knapsack, cryptosystem, merkle, mceliece, lamport, ies, hfe, epoc, ceilidh, others, falcon, sig, ntrusign, ntruencrypt, newhope, kyber, bliss, sis, lwe, lattice, svp, cvp, sts, srp, speke, schnorr, mqv, elgamal, eke, ecmqv, eddsa, ecdsa, dsa, cramer, shoup, bls, schmidt, samoa, okamoto, uchiyama, rabin, paillier, micali, gmr, damgård, jurik, cayley, purser, blum, benaloh, integer, factorization, official, website, nidhi, rastogi, james, hendler, role, metadata, preserving, 1701, 06817, arxiv, overview, roger, dingledine, nick, mathewson, specifications, steve, gibson, chiark, greenend, change, now, offers, advanced, speeds, how, does, implement, depend, friedl, markus, bsd, cross, usr, bin, kexalgs, timothy, moving, towards, signed, getmonero, mrl, 0003, mysterious, platform, 2022, ipfs_keystore, master, zzz, bahtiar, gadimov, multi, message, object, matt, johnston, cat, bring_the_noise, 079f36664caf1d1deb0af56e596e3bffbc7dde1b, permissionlesstech, straub, andreas, java, pure, rust, operations, ristretto255, july, ecdhe, 0ad90c3, series, justinha, docs, microsoft, ssp, randombit, net, lib, pubkey, cpp, source, embedded, ssl, products, limited, arm, tech, updates, previously, doxygen, documentation, fossies, nettle, methods, announcement, werner, koch, rescorla, rfc8446, levine, 8463, rfc8463, domainkeys, identified, assigned, authority, system, recommendations, regenscheid, andrew, withdrawn, 241055751, s2cid, 6028, pub, transition, plans, establishment, schemes, harris, velvindron, 8709, rfc8709, josefsson, sjd, baushke, juniper, networks, 8731, rfc8731, aris, introduces, sha256, things, rigidity, maxwell, gregory, green, matthew, cryptographyengineering, few, thoughts, engineering, flaws, kelsey, dual, kurosawa, kaoru, 4833, berlin, 2565722, 76899, 76900, 2_3, addition, doubling, 2011, choosing, safe, explicit, formulas, database, genus, large, characteristic, yung, moti, dodis, yevgeniy, kiayias, aggelos, eds, 3958, york, 228, 2423191, 33851, 11745853_14, 207, pkc, records, nath, kaushik, sarkar, palash, 985, arithmetic, fields, cfrg, naming, computes, very, state, art, irrelevant, exclusive, compiled, without, sign, releases, incognito, mode, secret, 1607, server, wire, tinyterm, tinyssh, instant, sshj, smartftp, silent, phone, signify, ios, ipfs, i2p, google, allo, facebook, dnscurve, android, application, zcash, tox, matrix, extension, jabber, xmpp, bouncy, castle, dalek, libressl, formerly, gnutls, nacl, libssh2, amended, also, standard, recommends, assigning, 8080, announced, would, added, which, specifies, federal, government, are, intention, update, become, alternative, being, wide, variety, defaults, adds, keys, signing, eventually, standardized, facto, bruce, believe, manipulated, through, their, relationships, industry, interest, began, increase, considerably, discovered, potentially, into, while, directly, suspicious, aspects, led, concerns, chosen, values, gave, advantage, backdoor, 2005, twisted, edwards, birationally, equivalent, constructed, such, avoids, potential, pitfalls, compressed, ladder, 486662, over, hence, numeric, base, generates, cyclic, whose, factor, meaning, elements, prevents, mounting, attack, pohlig, field, paper, underlying, offering, 128, bit, designed, agreement, one, fastest, covered, any, known, software, bits, free, encyclopedia, item, other, projects, printable, download, print, export, switch, legacy, parser, get, shortened, url, information, permanent, here, general, actions, english, русский, português, 한국어, 日本語, italiano, עברית, français, español, deutsch, čeština, català, top, personal, pages, recent, community, portal, learn, contribute, random, current, events, navigation, jump, content,
Text of the page (random words):
curve25519 wikipedia jump to content main menu main menu move to sidebar hide navigation main page contents current events random article about wikipedia contact us contribute help learn to edit community portal recent changes upload file special pages search search appearance donate create account log in personal tools donate create account log in contents move to sidebar hide top 1 mathematical properties 2 history 3 libraries 4 protocols 5 applications 6 notes 7 references 8 external links toggle the table of contents curve25519 12 languages català čeština deutsch español français עברית italiano 日本語 한국어 português русский 中文 edit links article talk english read edit view history tools tools move to sidebar hide actions read edit view history general what links here related changes upload file permanent link page information cite this page get shortened url switch to legacy parser print export download as pdf printable version in other projects wikidata item appearance move to sidebar hide from wikipedia the free encyclopedia elliptic curve used in internet cryptography in cryptography curve25519 is an elliptic curve used in elliptic curve cryptography ecc offering 128 bits of security 256 bit key size and designed for use with the elliptic curve diffie hellman ecdh key agreement scheme first described and implemented by daniel j bernstein it is one of the fastest curves in ecc and is not covered by any known patents 1 the reference implementation is public domain software 2 3 the original curve25519 paper defined it as a diffie hellman dh function bernstein has since proposed that the name curve25519 be used for the underlying curve and the name x25519 for the dh function 4 mathematical properties edit the curve used is y 2 x 3 486662 x 2 x a montgomery curve over the prime field defined by the pseudo mersenne prime number 5 2 255 19 displaystyle 2 255 19 hence the numeric 25519 in the name and it uses the base point with x 9 displaystyle x 9 this point generates a cyclic subgroup whose order is the prime 2 252 27742317777372353535851937790883648493 displaystyle 2 252 27742317777372353535851937790883648493 this subgroup has a co factor of 8 meaning the number of elements in the subgroup is 1 8 that of the elliptic curve group using a prime order subgroup prevents mounting a pohlig hellman algorithm attack 6 the protocol uses compressed elliptic point only x coordinates so it allows efficient use of the montgomery ladder for ecdh using only xz coordinates 7 curve25519 is constructed such that it avoids many potential implementation pitfalls 8 the curve is birationally equivalent to a twisted edwards curve used in the ed25519 9 10 signature scheme 11 history edit in 2005 curve25519 was first released by daniel j bernstein 6 in 2013 interest began to increase considerably when it was discovered that the nsa had potentially implemented a backdoor into the p 256 curve based dual_ec_drbg algorithm 12 while not directly related 13 suspicious aspects of the nist s p curve constants 14 led to concerns 15 that the nsa had chosen values that gave them an advantage in breaking the encryption 16 17 i no longer trust the constants i believe the nsa has manipulated them through their relationships with industry bruce schneier the nsa is breaking most encryption on the internet 2013 since 2013 curve25519 has become the de facto alternative to p 256 being used in a wide variety of applications 18 starting in 2014 openssh 19 defaults to curve25519 based ecdh and gnupg adds support for ed25519 keys for signing and encryption 20 the use of the curve was eventually standardized for both key exchange and signature in 2020 21 22 in 2017 nist announced that curve25519 and curve448 would be added to special publication 800 186 which specifies approved elliptic curves for use by the us federal government 23 both are described in rfc 7748 24 a 2019 draft of fips 186 5 notes the intention to allow usage of ed25519 25 for digital signatures the 2023 update of special publication 800 186 allows usage of curve25519 26 in february 2017 the dnssec specification for using ed25519 and ed448 was published as rfc 8080 assigning algorithm numbers 15 and 16 27 in 2018 dkim specification was amended so as to allow signatures with this algorithm 28 also in 2018 rfc 8446 was published as the new transport layer security v1 3 standard it recommends support for x25519 ed25519 x448 and ed448 algorithms 29 libraries edit libgcrypt 30 libssh 19 31 libssh2 since version 1 9 0 nacl 32 gnutls 33 mbed tls formerly polarssl 34 wolfssl 35 botan 36 schannel a 37 libsodium 38 openssl since version 1 1 0 39 libressl 40 nss since version 3 28 41 crypto curve25519 dalek 42 bouncy castle 43 protocols edit omemo a proposed extension for xmpp jabber 44 secure shell signal protocol matrix protocol tox zcash transport layer security wireguard applications edit bitchat 45 conversations android application b cryptocat 46 b dnscrypt 47 dnscurve dnssec dropbear 31 48 facebook messenger c d gajim via plugin 49 b gnunet 50 gnupg google allo e d i2p 51 ipfs 52 ios 53 monero 54 openbsd and signify f openssh 31 g peerio 59 proton mail 60 putty 61 signal d silent phone smartftp 31 sshj 31 sqrl 62 threema instant messenger 63 tinyssh 31 tinyterm 31 tor 64 viber 65 whatsapp d 66 wire wireguard notes edit starting with windows 10 1607 windows server 2016 1 2 3 via the omemo protocol only in secret conversations 1 2 3 4 via the signal protocol only in incognito mode used to sign releases and packages 55 56 exclusive key exchange in openssh 6 7 when compiled without openssl 57 58 references edit bernstein irrelevant patents on elliptic curve cryptography cr yp to retrieved 2016 02 08 a state of the art diffie hellman function by daniel j bernstein my curve25519 library computes the curve25519 function at very high speed the library is in the public domain x25519 crypto 5 march 2019 retrieved 3 february 2023 cite web cs1 maint deprecated archival service link cfrg 25519 naming retrieved 2016 02 25 nath kaushik sarkar palash 2018 efficient arithmetic in pseudo mersenne prime order fields 2018 985 retrieved 2025 05 10 1 2 bernstein daniel j 2006 curve25519 new diffie hellman speed records pdf in yung moti dodis yevgeniy kiayias aggelos et al eds public key cryptography pkc 2006 public key cryptography lecture notes in computer science vol 3958 new york springer pp 207 228 doi 10 1007 11745853_14 isbn 978 3 540 33851 2 mr 2423191 lange tanja efd genus 1 large characteristic xz coordinates for montgomery curves efd explicit formulas database retrieved 2016 02 08 bernstein daniel j lange tanja 2017 01 22 safecurves introduction safecurves choosing safe curves for elliptic curve cryptography retrieved 2016 02 08 bernstein daniel j duif niels lange tanja schwabe peter yang bo yin 2017 01 22 ed25519 high speed high security signatures retrieved 2019 11 09 bernstein daniel j duif niels lange tanja schwabe peter yang bo yin 2011 09 26 high speed high security signatures pdf retrieved 2019 11 09 bernstein daniel j lange tanja 2007 faster addition and doubling on elliptic curves in kurosawa kaoru ed advances in cryptology asiacrypt 2007 advances in cryptology asiacrypt lecture notes in computer science vol 4833 berlin springer pp 29 50 doi 10 1007 978 3 540 76900 2_3 isbn 978 3 540 76899 9 mr 2565722 kelsey john may 2014 dual ec in x9 82 and sp 800 90 pdf national institute of standards in technology retrieved 2018 12 02 green matthew 2015 01 14 a few thoughts on cryptographic engineering the many flaws of dual_ec_drbg blog cryptographyengineering com retrieved 2015 05 20 safecurves introduction maxwell gregory 2013 09 08 tor talk nist approved crypto in tor retrieved 2015 05 20 safecurves rigidity safecurves cr yp to retrieved 2015 05 20 the nsa is breaking most encryption on the internet schneier on security www schneier com 5 september 2013 retrieved 2015 05 20 things that use curve25519 retrieved 2015 12 23 1 2 adamantiadis aris 2013 11 03 openssh introduces curve25519 sha256 libssh org key exchange libssh org retrieved 2014 12 27 gnupg what s new in 2 1 august 2021 a adamantiadis libssh s josefsson sjd ab m baushke juniper networks inc february 2020 secure shell ssh key exchange method using curve25519 and curve448 ietf doi 10 17487 rfc8731 rfc 8731 b harris l velvindron february 2020 ed25519 and ed448 public key algorithms for the secure shell ssh protocol ietf doi 10 17487 rfc8709 rfc 8709 transition plans for key establishment schemes national institute of standards and technology 2017 10 31 archived from the original on 2018 03 11 retrieved 2019 09 04 rfc 7748 retrieved from rfc 7748 regenscheid andrew 31 october 2019 fips pub 186 5 national institute of standards and technology withdrawn draft doi 10 6028 nist fips 186 5 draft s2cid 241055751 recommendations for discrete logarithm based cryptography pdf domain name system security dnssec algorithm numbers internet assigned numbers authority 2024 12 05 retrieved 2024 12 27 john levine september 2018 a new cryptographic signature method for domainkeys identified mail dkim ietf doi 10 17487 rfc8463 rfc 8463 e rescorla september 2018 the transport layer security tls protocol version 1 3 ietf doi 10 17487 rfc8446 rfc 8446 werner koch 15 april 2016 libgcrypt 1 7 0 release announcement retrieved 22 april 2016 1 2 3 4 5 6 7 ssh implementation comparison comparison of key exchange methods retrieved 2016 02 25 introduction yp to retrieved 11 december 2014 nettle curve25519 h file reference fossies doxygen documentation archived from the original on 2015 05 20 retrieved 2015 05 19 limited arm polarssl 1 3 3 released tech updates mbed tls previously polarssl tls mbed org retrieved 2015 05 19 cite web last has generic name help wolfssl embedded ssl tls library products wolfssl 4 august 2017 botan src lib pubkey curve25519 curve25519 cpp source file botan randombit net justinha tls schannel ssp docs microsoft com retrieved 2017 09 15 denis frank introduction libsodium libsodium org openssl 1 1 0 series release notes openssl foundation archived from the original on 2018 03 17 retrieved 2016 06 24 add support for ecdhe with x25519 openbsd src 0ad90c3 github nss 3 28 release notes archived from the original on 9 december 2017 retrieved 25 july 2017 a pure rust implementation of group operations on ristretto255 and curve25519 github retrieved 14 april 2021 ed25519 java github 13 october 2021 straub andreas 25 october 2015 omemo encryption conversations im bitchat bring_the_noise md at 079f36664caf1d1deb0af56e596e3bffbc7dde1b permissionlesstech bitchat github retrieved 2025 07 19 cryptocat security crypto cat archived from the original on 2016 04 07 retrieved 2016 05 24 frank denis dnscrypt version 2 protocol specification github archived from the original on 2015 08 13 retrieved 2016 03 03 matt johnston dropbear ssh changes retrieved 2016 02 25 bahtiar gadimov et al gajim plugin for omemo multi end message and object encryption github retrieved 2016 10 01 gnunet 0 10 0 gnunet org archived from the original on 9 december 2017 retrieved 11 december 2014 zzz 2014 09 20 0 9 15 release blog retrieved 20 december 2014 go ipfs_keystore go at master github com 30 march 2022 apple platform security apple support mrl 0003 monero is not that mysterious pdf getmonero com archived from the original pdf on 2019 05 01 retrieved 2018 06 05 murenin constantine a 2014 01 19 soulskill ed openbsd moving towards signed packages based on d j bernstein crypto slashdot retrieved 2014 12 27 murenin constantine a 2014 05 01 timothy ed openbsd 5 5 released slashdot retrieved 2014 12 27 friedl markus 2014 04 29 ssh kex c kexalgs bsd cross reference openbsd src usr bin retrieved 2014 12 27 murenin constantine a 2014 04 30 soulskill ed openssh no longer has to depend on openssl slashdot retrieved 2014 12 26 how does peerio implement end to end encryption peerio archived from the original on 2017 12 09 retrieved 2015 11 04 proton mail now offers elliptic curve cryptography for advanced security and faster speeds 25 april 2019 putty change log www chiark greenend org uk steve gibson december 2019 sqrl cryptography whitepaper pdf threema cryptography whitepaper pdf roger dingledine nick mathewson tor s protocol specifications blog retrieved 20 december 2014 viber encryption overview viber 3 may 2016 retrieved 24 september 2016 nidhi rastogi james hendler 2017 01 24 whatsapp security and role of metadata in preserving privacy arxiv 1701 06817 cs cr external links edit official website v t e public key cryptography algorithms integer factorization benaloh blum goldwasser cayley purser damgård jurik gmr goldwasser micali naccache stern paillier rabin rsa okamoto uchiyama schmidt samoa discrete logarithm bls cramer shoup dh dsa ecdh x25519 x448 ecdsa eddsa ed25519 ed448 ecmqv eke elgamal signature scheme mqv schnorr speke srp sts lattice svp cvp lwe sis bliss kyber newhope ntruencrypt ntrusign rlwe kex rlwe sig falcon others ae ceilidh epoc hfe ies lamport mceliece merkle hellman naccache stern knapsack cryptosystem three pass protocol xtr sqisign sphincs theory discrete logarithm cryptography elliptic curve cryptography hash based cryptography non commutative cryptography rsa problem trapdoor function tropical cryptography standardization cryptrec ieee p1363 nessie nsa suite b cnsa post quantum cryptography topics digital signature oaep fingerprint pki web of trust key size identity based cryptography post quantum cryptography openpgp card retrieved from https en wikipedia org w index php title curve25519 oldid 1374209302 category elliptic curves hidden categories articles with short description short description matches wikidata cs1 maint deprecated archival service cs1 errors generic name this page was last edited on 10 september 2026 at 14 44 utc page was rendered with parsoid text is available under the creative commons attribution sharealike 4 0 license additional terms may apply by using this site you agree to the terms of use and privacy policy wikipedia is a registered trademark of the wikimedia foundation inc a non profit organization privacy policy about wikipedia disclaimers contact wikipedia legal safety contacts code of conduct developers statistics cookie statement mobile view search search toggle the table of contents curve25519 12 languages add topic
|