The ristretto255 and decaf448 Groups

The information below is for an old version of the document
Document Type Expired Internet-Draft (cfrg RG)
Authors Henry de Valence  , Jack Grigg  , George Tankersley  , Filippo Valsorda  , Isis Lovecruft  , Mike Hamburg 
Last updated 2021-04-08 (latest revision 2020-10-05)
Replaces draft-irtf-cfrg-ristretto255
Stream Internet Research Task Force (IRTF)
Expired & archived
plain text html xml pdf htmlized bibtex
Stream IRTF state (None)
Consensus Boilerplate Unknown
Document shepherd No shepherd assigned
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448.


Henry de Valence (
Jack Grigg (
George Tankersley (
Filippo Valsorda (
Isis Lovecruft (
Mike Hamburg (

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)