CACrown ArchivesThe cinema collection
Menu
Research dossier · General Reference

EdDSA

digital signature scheme

Cross-disciplinary reference desk with index cards, atlas, dictionary and catalogue
General referenceInterpretive dossier study · Crown Archives visual atlas
Record originEnglish Wikipedia
Text licenseCC BY-SA 4.0
Source revisionMar 22, 2026
Entity authorityQ16966748
Source-derived summary

In public-key cryptography, Edwards-curve Digital Signature Algorithm (EdDSA) is a digital signature scheme using a variant of Schnorr signature based on twisted Edwards curves.

It is designed to be faster than existing digital signature schemes without sacrificing security. It was developed by a team including Daniel J. Bernstein, Niels Duif, Tanja Lange, Peter Schwabe, and Bo-Yin Yang.

The reference implementation is public-domain software.

Summary

The following is a simplified description of EdDSA, ignoring details of encoding integers and curve points as bit strings; the full details are in the papers and RFC.

An EdDSA signature scheme is a choice:

of finite field

F

q

{\displaystyle \mathbb {F} _{q}}

over odd prime power

q

{\displaystyle q}

;

of elliptic curve

E

{\displaystyle E}

over

F

q

{\displaystyle \mathbb {F} _{q}}

whose group

E

(

F

q

)

{\displaystyle E(\mathbb {F} _{q})}

of

F

q

{\displaystyle \mathbb {F} _{q}}

-rational points has order

#

E

(

F

q

)

=

2

c

{\displaystyle \#E(\mathbb {F} _{q})=2^{c}\ell }

, where

{\displaystyle \ell }

is a large prime and

2

c

{\displaystyle 2^{c}}

is called the cofactor;

of base point

B

E

(

F

q

)

{\displaystyle B\in E(\mathbb {F} _{q})}

with order

{\displaystyle \ell }

; and

of cryptographic hash function

H

{\displaystyle H}

with

2

b

{\displaystyle 2b}

-bit outputs, where

2

b

1

>

q

{\displaystyle 2^{b-1}>q}

so that elements of

F

q

{\displaystyle \mathbb {F} _{q}}

and curve points in

E

(

F

q

)

{\displaystyle E(\mathbb {F} _{q})}

can be represented by strings of

b

{\displaystyle b}

bits.

These parameters are common to all users of the EdDSA signature scheme. The security of the EdDSA signature scheme depends critically on the choices of parameters, except for the arbitrary choice of base point—for example, Pollard's rho algorithm for logarithms is expected to take approximately

π

/

4

{\displaystyle {\sqrt {\ell \pi /4}}}

curve additions before it can compute a discrete logarithm, so

{\displaystyle \ell }

must be large enough for this to be infeasible, and is typically taken to exceed 2200.

The choice of

{\displaystyle \ell }

is limited by the choice of

q

{\displaystyle q}

, since by Hasse's theorem,

#

E

(

F

q

)

=

2

c

{\displaystyle \#E(\mathbb {F} _{q})=2^{c}\ell }

cannot differ from

q

+

1

{\displaystyle q+1}

by more than

2

q

{\displaystyle 2{\sqrt {q}}}

. The hash function

H

{\displaystyle H}

is normally modelled as a random oracle in formal analyses of EdDSA's security.

Within an EdDSA signature scheme,

Public key

An EdDSA public key is a curve point

A

E

(

F

q

)

{\displaystyle A\in E(\mathbb {F} _{q})}

, encoded in

b

{\displaystyle b}

bits.

Editorial summary

“EdDSA” enters the record as digital signature scheme. Crown Archives preserves that source wording while asking what EdDSA, digital and signature can confirm, complicate or overturn.

Editorial reviewA practical starting point whose main value is the path it opens into stronger specialist and primary sources. The current 454-word lead offers orientation but no explicit four-digit date, so chronology should not be assumed. The selected authority fields contribute no independent date. Its strongest next move is a source search built around EdDSA, digital and signature.
Editorial analysis

Why this record matters

“EdDSA” is worth following because a concise public description often conceals a longer documentary argument. Here, EdDSA, digital and signature provides the most credible route into that argument.

Evidence profile

Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Mar 22, 2026. The linked authority identifier is Q16966748. None of the 0 selected statements returned an explicit reference.

Critical limits

Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.

How to read it

Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.

Best used for
  • Subject orientation
  • Search vocabulary
  • Locating named sources
Verify next

The closest primary source, responsible institution and strongest cited specialist reference.

Three-step research path

  1. Establish the record: confirm the title “EdDSA”, its source revision and the description used here.
  2. Expand the search: follow EdDSA primary sources, EdDSA archive and EdDSA research across catalogues and specialist indexes.
  3. Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.

Questions for further research

  1. Which source most directly establishes the central claim about “EdDSA”?
  2. Which cited source is closest to the event, object or claim?
  3. Which institution is responsible for the underlying evidence?
Subject index

Search terms from this dossier

Source & attribution

This entry incorporates text from EdDSA” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.