Glossary

Ed25519

Ed25519 is a digital signature algorithm that uses the twisted Edwards curve edwards25519 and SHA-512, with 32-byte public keys and 64-byte signatures. It is the Edwards-curve Digital Signature Algorithm (EdDSA) variant defined in RFC 8032, and it targets about 128 bits of security. A signature depends only on the key and the message, so signing the same input twice gives identical bytes.

How it works

The private key is 32 random bytes, called the seed. The signer hashes the seed with SHA-512 and splits the 64-byte result. The first half, with some bits cleared and set, becomes a secret scalar, and the second half becomes a prefix. The public key is that scalar times the base point, packed into 32 bytes.

To sign, the algorithm hashes the prefix together with the message to get a nonce r, so no random number generator is needed at signing time. The signature has two 32-byte halves, R and S. R is the nonce point and S combines the nonce, the key and a hash of R, the public key and the message.

RFC 8032 lists three variants. Plain Ed25519 signs the whole message. Ed25519ph signs a SHA-512 hash of it, and Ed25519ctx adds a context string. Plain Ed25519 is the one TLS, SSH and most libraries expose.

The script below signs an empty message with the first test key in RFC 8032, and both the public key and the signature match that RFC.

from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives import serialization as s
sk=Ed25519PrivateKey.from_private_bytes(bytes.fromhex("9d61b19deffd5a60ba844af492ec2cc44449c5697b326919703bac031cae7f60"))
pub=sk.public_key().public_bytes(s.Encoding.Raw,s.PublicFormat.Raw)
sig=sk.sign(b"")
print("public:", pub.hex(), len(pub))
print("sig   :", sig.hex(), len(sig))
print("again identical:", sk.sign(b"")==sig)
public: d75a980182b10ab7d54bfed3c964073a0ee172f3daa62325af021a68f707511a 32
sig   : e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b 64
again identical: True

What is the size of an Ed25519 key and signature?

An Ed25519 private key is 32 bytes, the public key is 32 bytes and the signature is 64 bytes. Contrast that with RSA-2048, whose signature is 256 bytes, and with P-256 ECDSA, whose raw signature is also 64 bytes but varies from 70 to 72 bytes in DER. Some APIs return a 64-byte private key, which is the 32-byte seed followed by the public key, so check which form a library means.

Ed25519 vs ECDSA

Ed25519 differs from ECDSA mainly in how the nonce is made and in how verification behaves. ECDSA needs a good random k for every signature, while Ed25519 derives it from the key and message. RFC 8032 notes that EdDSA formulas are complete, so verification needs no separate point validation, and signatures resist the hash collisions that hurt pure hash-then-sign schemes. Verification also rejects any S that is not smaller than the group order, which stops signature malleability (RFC 8032, section 8.4).

TLS 1.3 assigns Ed25519 the signature scheme code 0x0807 (RFC 8446), and RFC 8709 defines it for SSH.

Common pitfalls

  • Confusing Ed25519 with X25519: Ed25519 signs and X25519 agrees on a key. Both use Curve25519 math but the keys are not interchangeable in the API.
  • Handing a library the wrong key length: 32 bytes is a seed, 64 bytes in some libraries is seed plus public key, and PEM files add an ASN.1 wrapper. A mismatch fails with a length error.
  • Expecting a prehash or context by default: plain Ed25519 verifies only against plain Ed25519. A signature made with Ed25519ph does not verify as plain Ed25519.
  • Assuming it resists quantum computers: RFC 8032 states that a large enough quantum computer breaks both Ed25519 and Ed448.
  • Accepting non-canonical signatures: a verifier that skips the S below group order check accepts a second valid signature for the same message.

Related terms

  • ECC — the family of curve-based methods that Ed25519 belongs to.
  • ECDSA — the older curve signature scheme that needs a random value per signature.
  • RSA — the factoring-based alternative with 256-byte signatures at 2048 bits.
  • SSH key — Ed25519 is a common key type generated by ssh-keygen.
  • TLS — supports Ed25519 as a signature scheme in version 1.3.
  • SHA-512 — the hash inside Ed25519.

See also