Twisted Edwards Curves
Twisted Edwards curves are parameterized by a,d and are of the form
Ea,d:ax2+y2=1+dx2y2.
These are usually represented by the Extended Twisted Edwards Coordinates of Hisil, Wong, Carter, and Dawson: points are represented in projective coordinates as (X:Y:Z:T) with
XY=ZT, aX2+Y2=Z2+dT2.
(More details on Edwards curve models can be found in the curve25519_dalek curve_models documentation). The case a=1 is the untwisted case; the case a=−1 provides the fastest formulas. When not otherwise specified, we E for Ea,d .
When both d and ad are nonsquare (which forces a to be square), the curve is complete. In this case the four-torsion subgroup is cyclic, and we can write it explicitly as
Ea,d[4]={(0,1),(1/a,0),(0,−1),(−1/a,0)}
These are the only points with xy=0 ; the points with y=0 are 2-torsion.
Last updated
Was this helpful?