Curve448
E831085
Curve448 is a high-security elliptic curve designed for modern cryptographic protocols, particularly for efficient and secure key exchange and digital signatures.
Observed surface forms (1)
| Surface form | Occurrences |
|---|---|
| Edwards-curve Digital Signature Algorithm over Curve448 | 1 |
Statements (47)
| Predicate | Object |
|---|---|
| instanceOf |
cryptographic primitive
ⓘ
elliptic curve ⓘ public-key cryptography scheme ⓘ |
| alias | Goldilocks curve NERFINISHED ⓘ |
| applicationDomain |
Transport Layer Security (TLS)
NERFINISHED
ⓘ
VPN protocols ⓘ secure messaging protocols ⓘ |
| basePointOrder | large prime order subgroup ⓘ |
| belongsToFamily | safe-curves ⓘ |
| bitLength | 448 bits ⓘ |
| cofactor | 4 ⓘ |
| comparedTo | Curve25519 NERFINISHED ⓘ |
| coordinateSystem | Montgomery coordinates ⓘ |
| cryptographicStrength | intended to be secure against large-scale classical adversaries ⓘ |
| curveEquationType | Montgomery form y^2 = x^3 + Ax^2 + x over F_p ⓘ |
| curveForm | Montgomery curve NERFINISHED ⓘ |
| designedFor |
digital signatures
ⓘ
high-security applications ⓘ key exchange ⓘ modern cryptographic protocols ⓘ |
| designObjective |
high performance at high security level
ⓘ
simple, auditable specification ⓘ |
| fieldCharacteristic | 2^448 - 2^224 - 1 ⓘ |
| fieldType | prime field ⓘ |
| introducedBy | Mike Hamburg NERFINISHED ⓘ |
| introducedIn | 2015 ⓘ |
| mathematicalStructure | group of points over a finite field ⓘ |
| notDesignedFor | post-quantum security ⓘ |
| offersHigherSecurityThan | Curve25519 NERFINISHED ⓘ |
| primeFieldSize | 448-bit prime ⓘ |
| property |
designed to avoid implementation pitfalls
ⓘ
rigidly defined curve parameters ⓘ supports constant-time implementations ⓘ |
| recommendedBy | IETF NERFINISHED ⓘ |
| relatedStandard | TLS 1.3 recommended groups ⓘ |
| securityGoal |
resistance to known classical attacks on elliptic curves
ⓘ
side-channel resistance in typical implementations ⓘ |
| securityLevel | approximately 224-bit security ⓘ |
| standardizedIn |
RFC 7748
NERFINISHED
ⓘ
RFC 8032 NERFINISHED ⓘ |
| supportsProtocol |
Ed448
NERFINISHED
ⓘ
X448 ⓘ |
| usedFor |
Diffie–Hellman key exchange
NERFINISHED
ⓘ
Elliptic Curve Diffie–Hellman (ECDH) NERFINISHED ⓘ digital signature schemes ⓘ |
| usedIn |
Ed448 signature scheme
NERFINISHED
ⓘ
X448 key agreement scheme ⓘ |
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.