EdDSA
digital signature scheme

In public-key cryptography, Edwards-curve Digital Signature Algorithm (EdDSA) is a digital signature scheme using a variant of Schnorr signature based on twisted Edwards curves.
It is designed to be faster than existing digital signature schemes without sacrificing security. It was developed by a team including Daniel J. Bernstein, Niels Duif, Tanja Lange, Peter Schwabe, and Bo-Yin Yang.
The reference implementation is public-domain software.
Summary
The following is a simplified description of EdDSA, ignoring details of encoding integers and curve points as bit strings; the full details are in the papers and RFC.
An EdDSA signature scheme is a choice:
of finite field
F
q
{\displaystyle \mathbb {F} _{q}}
over odd prime power
q
{\displaystyle q}
;
of elliptic curve
E
{\displaystyle E}
over
F
q
{\displaystyle \mathbb {F} _{q}}
whose group
E
(
F
q
)
{\displaystyle E(\mathbb {F} _{q})}
of
F
q
{\displaystyle \mathbb {F} _{q}}
-rational points has order
#
E
(
F
q
)
=
2
c
ℓ
{\displaystyle \#E(\mathbb {F} _{q})=2^{c}\ell }
, where
ℓ
{\displaystyle \ell }
is a large prime and
2
c
{\displaystyle 2^{c}}
is called the cofactor;
of base point
B
∈
E
(
F
q
)
{\displaystyle B\in E(\mathbb {F} _{q})}
with order
ℓ
{\displaystyle \ell }
; and
of cryptographic hash function
H
{\displaystyle H}
with
2
b
{\displaystyle 2b}
-bit outputs, where
2
b
−
1
>
q
{\displaystyle 2^{b-1}>q}
so that elements of
F
q
{\displaystyle \mathbb {F} _{q}}
and curve points in
E
(
F
q
)
{\displaystyle E(\mathbb {F} _{q})}
can be represented by strings of
b
{\displaystyle b}
bits.
These parameters are common to all users of the EdDSA signature scheme. The security of the EdDSA signature scheme depends critically on the choices of parameters, except for the arbitrary choice of base point—for example, Pollard's rho algorithm for logarithms is expected to take approximately
ℓ
π
/
4
{\displaystyle {\sqrt {\ell \pi /4}}}
curve additions before it can compute a discrete logarithm, so
ℓ
{\displaystyle \ell }
must be large enough for this to be infeasible, and is typically taken to exceed 2200.
The choice of
ℓ
{\displaystyle \ell }
is limited by the choice of
q
{\displaystyle q}
, since by Hasse's theorem,
#
E
(
F
q
)
=
2
c
ℓ
{\displaystyle \#E(\mathbb {F} _{q})=2^{c}\ell }
cannot differ from
q
+
1
{\displaystyle q+1}
by more than
2
q
{\displaystyle 2{\sqrt {q}}}
. The hash function
H
{\displaystyle H}
is normally modelled as a random oracle in formal analyses of EdDSA's security.
Within an EdDSA signature scheme,
Public key
An EdDSA public key is a curve point
A
∈
E
(
F
q
)
{\displaystyle A\in E(\mathbb {F} _{q})}
, encoded in
b
{\displaystyle b}
bits.
“EdDSA” enters the record as digital signature scheme. Crown Archives preserves that source wording while asking what EdDSA, digital and signature can confirm, complicate or overturn.
Why this record matters
“EdDSA” is worth following because a concise public description often conceals a longer documentary argument. Here, EdDSA, digital and signature provides the most credible route into that argument.
Vocabulary and entity names are the principal evidence signals here, because they determine the precision of every later search. The source revision retrieved here is dated Mar 22, 2026. The linked authority identifier is Q16966748. None of the 0 selected statements returned an explicit reference.
Overview language is designed for orientation and should not be treated as a substitute for the evidence cited beneath it. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Use the entry as an orientation point, then follow its citations and revision history. Names, dates and institutional relationships should be checked against the original record.
- Subject orientation
- Search vocabulary
- Locating named sources
The closest primary source, responsible institution and strongest cited specialist reference.
Three-step research path
- Establish the record: confirm the title “EdDSA”, its source revision and the description used here.
- Expand the search: follow EdDSA primary sources, EdDSA archive and EdDSA research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “EdDSA”?
- Which cited source is closest to the event, object or claim?
- Which institution is responsible for the underlying evidence?
Search terms from this dossier
This entry incorporates text from “EdDSA” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.