Twisted Edwards Curves
Last updated
Last updated
Twisted Edwards curves are parameterized by and are of the form
These are usually represented by the Extended Twisted Edwards Coordinates of Hisil, Wong, Carter, and Dawson: points are represented in projective coordinates as with
(More details on Edwards curve models can be found in the curve25519_dalek
curve_models
documentation). The case is the untwisted case; the case provides the fastest formulas. When not otherwise specified, we for .
When both and are nonsquare (which forces to be square), the curve is complete. In this case the four-torsion subgroup is cyclic, and we can write it explicitly as
These are the only points with ; the points with are 2-torsion.