Curve25519
More info
- Creator
- Daniel J. Bernstein
- Released
- Type
- Elliptic curve
- License
- Public domain
- Spec
- RFC 7748
- Wikipedia
- en.wikipedia.org
The Montgomery curve that underlies X25519 (Diffie-Hellman key exchange) and Ed25519 (signatures) — designed by DJB in 2005 for speed and footgun resistance.
Parameters chosen according to strict, public criteria (unlike NIST P-curves whose curves have "magic" constants). 128-bit security level, naturally constant-time, no "point-at-infinity" special case, no coordinate validation needed.
Powers TLS 1.3, Signal, WhatsApp, Tor, WireGuard, age, SSH. A practical monopoly on "modern ECC" — every time you see X25519 or Ed25519 in a handshake, this is the curve doing the work.