@misc{rfc9496, series = {Request for Comments}, number = 9496, howpublished = {RFC 9496}, publisher = {RFC Editor}, doi = {10.17487/RFC9496}, url = {https://www.rfc-editor.org/info/rfc9496}, author = {Henry de Valence and Jack Grigg and Mike Hamburg and Isis Lovecruft and George Tankersley and Filippo Valsorda}, title = {{The ristretto255 and decaf448 Groups}}, pagetotal = 27, year = 2023, month = dec, abstract = {This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448. This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.}, }