HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulecryptonite-0.30Haskell2010

Crypto.ECC.Edwards25519

Arithmetic primitives over curve edwards25519.

Twisted Edwards curves are a familly of elliptic curves allowing complete addition formulas without any special case and no point at infinity. Curve edwards25519 is based on prime 2^255 - 19 for efficient implementation. Equation and parameters are given in RFC 7748.

This module provides types and primitive operations that are useful to implement cryptographic schemes based on curve edwards25519:

  • arithmetic functions for point addition, doubling, negation, scalar multiplication with an arbitrary point, with the base point, etc.

  • arithmetic functions dealing with scalars modulo the prime order L of the base point

All functions run in constant time unless noted otherwise.

Warnings:

  1. Curve edwards25519 has a cofactor h = 8 so the base point does not generate the entire curve and points with order 2, 4, 8 exist. When implementing cryptographic algorithms, special care must be taken using one of the following methods:

    • points must be checked for membership in the prime-order subgroup

    • or cofactor must be cleared by multiplying points by 8

    Utility functions are provided to implement this. Testing subgroup membership with pointHasPrimeOrder is 50-time slower than call pointMulByCofactor.

  2. Scalar arithmetic is always reduced modulo L, allowing fixed length and constant execution time, but this reduction is valid only when points are in the prime-order subgroup.

  3. Because of modular reduction in this implementation it is not possible to multiply points directly by scalars like 8.s or L. This has to be decomposed into several steps.

  • 2 types
  • 15 values
  • Packagecryptonite-0.30
  • Exports17
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceEdwards25519.hs
newtypenewtype Scalar
#

A scalar modulo prime order of curve edwards25519.

Instances3Eq, Show, NFData
  • Eq ScalarDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519
  • Show ScalarDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519
  • NFData ScalarDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519
newtypenewtype Point
#

A point on curve edwards25519.

Instances3Eq, Show, NFData
  • Eq PointDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519
  • Show PointDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519
  • NFData PointDefined in cryptonite-0.30 · Crypto.ECC.Edwards25519

Scalars

3 declarations

Deserialize a little-endian number as a scalar. Input array can have any length from 0 to 64 bytes.

Note: it is not advised to put secret information in the 3 lowest bits of a scalar if this scalar may be multiplied to untrusted points outside the prime-order subgroup.

Points

3 declarations

Arithmetic functions

9 declarations
valuepointMul :: Scalar -> Point -> Point
#

Scalar multiplication over curve edwards25519.

Note: when the scalar had reduction modulo L and the input point has a torsion component, the output point may not be in the expected subgroup.