The ristretto255 Group

Document Type Replaced Internet-Draft (cfrg RG)
Authors Henry de Valence  , Jack Grigg  , George Tankersley  , Filippo Valsorda  , Isis Lovecruft 
Last updated 2019-11-18 (latest revision 2019-05-08)
Replaced by draft-irtf-cfrg-ristretto255
Stream Internet Research Task Force (IRTF)
Intended RFC status (None)
Expired & archived
plain text xml pdf htmlized bibtex
Stream IRTF state Replaced
Consensus Boilerplate Unknown
Document shepherd No shepherd assigned
IESG IESG state Replaced by draft-irtf-cfrg-ristretto255
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This memo specifies a prime-order group, ristretto255, suitable for implementing complex cryptographic protocols such as zero-knowledge proofs. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group.


Henry de Valence (
Jack Grigg (
George Tankersley (
Filippo Valsorda (
Isis Lovecruft (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)