RFC 9496 · INFORMATIONAL · 2023

The ristretto255 and decaf448 Groups

Overview

RFC 9496, “The ristretto255 and decaf448 Groups”, is an Informational document published in December 2023 by H. de Valence, J. Grigg, M. Hamburg, I. Lovecruft, G. Tankersley, F. Valsorda. The canonical text is published by the RFC Editor.

Abstract

This memo specifies two prime-order groups, ristretto255 and decaf448, suitable for safely implementing higher-level and complex cryptographic protocols. The ristretto255 group can be implemented using Curve25519, allowing existing Curve25519 implementations to be reused and extended to provide a prime-order group. Likewise, the decaf448 group can be implemented using edwards448.

This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 9496 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2023

Who Is Online

In total there are 68 users online: 0 registered, 64 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354