General parameters (for all curve models): p 2^{255}-19 (=0x7fffffff ffffffff ffffffff ffffffff ffffffff ffffffff ffffffff ffffffed) h 8 n 723700557733226221397318656304299424085711635937990760600195093828 5454250989 (=2^{252} + 0x14def9de a2f79cd6 5812631a 5cf5d3ed) Montgomery curve-specific parameters (for Curve25519): A 486662 B 1 Gu 9 (=0x9) Gv 147816194475895447910205935684099868872646061346164752889648818377 55586237401 (=0x20ae19a1 b8a086b4 e01edd2c 7748d14c 923d4d7e 6d7c61b2 29e9c5a2 7eced3d9) Twisted Edwards curve-specific parameters (for Edwards25519): a -1 (-0x01) d -121665/121666 (=3709570593466943934313808350875456518954211387984321901638878553 3085940283555) (=0x52036cee 2b6ffe73 8cc74079 7779e898 00700a4d 4141d8ab 75eb4dca 135978a3) Gx 151122213495354007725011514095885315114540126930418572060461132839 49847762202 (=0x216936d3 cd6e53fe c0a4e231 fdd6dc5c 692cc760 9525a7b2 c9562d60 8f25d51a) Gy 4/5 (=4631683569492647816942839400347516314130799386625622561578303360 3165251855960) (=0x66666666 66666666 66666666 66666666 66666666 66666666 66666666 66666658) Weierstrass curve-specific parameters (for Wei25519): a 192986815395526992372618308347813179755449974442734273399095973345 73241639236 (=0x2aaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaa98 4914a144) b 557517466698189089076452890782571408182411037279010123152944008379 56729358436 (=0x7b425ed0 97b425ed 097b425e d097b425 ed097b42 5ed097b4 260b5e9c 7710c864) GX 192986815395526992372618308347813179755449974442734273399095973346 52188435546 (=0x2aaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaaaaaaa aaad245a) GY 147816194475895447910205935684099868872646061346164752889648818377 55586237401 (=0x20ae19a1 b8a086b4 e01edd2c 7748d14c 923d4d7e 6d7c61b2 29e9c5a2 7eced3d9) Acknowledgments Many thanks to Charlie Perkins for his in-depth review and constructive suggestions. The authors are also especially grateful to Robert Moskowitz and Benjamin Kaduk for their comments and discussions that led to many improvements. The authors wish to also thank Shwetha Bhandari for actively shepherding this document and Roman Danyliw, Alissa Cooper, Mirja Kuehlewind, Eric Vyncke, Vijay Gurbani, Al Morton, and Adam Montville for their constructive reviews during the IESG process. Finally, many thanks to our INT area ADs, Suresh Krishnan and Erik Kline, who supported us along the whole process. Authors' Addresses Pascal Thubert (editor) Cisco Systems, Inc Building D 45 Allee des Ormes - BP1200 06254 MOUGINS - Sophia Antipolis France Phone: +33 497 23 26 34 Email: pthubert@cisco.com Behcet Sarikaya Email: sarikaya@ieee.org Mohit Sethi Ericsson FI-02420 Jorvas Finland Email: mohit@piuha.net Rene Struik Struik Security Consultancy Email: rstruik.ext@gmail.com