The Provable Security of Ed25519: Theory and Practice
Jacqueline Brendel, Cas Cremers, Dennis Jackson, Mang Zhao
Abstract
A standard requirement for a signature scheme is that it is existentially unforgeable under chosen message attacks (EUF-CMA), alongside other properties of interest such as strong unforgeability (SUF-CMA), and resilience against key substitution attacks. Remarkably, no detailed proofs have ever been given for these security properties for EdDSA, and in particular its Ed25519 instantiations. Ed25519 is one of the most efficient and widely used signature schemes, and different instantiations of Ed25519 are used in protocols such as TLS 1.3, SSH, Tor, ZCash, and WhatsApp/Signal. The differences between these instantiations are subtle, and only supported by informal arguments, with many works assuming results can be directly transferred from Schnorr signatures. Similarly, several proofs of protocol security simply assume that Ed25519 satisfies properties such as EUF-CMA or SUF-CMA. In this work we provide the first detailed analysis and security proofs of Ed25519 signature schemes. While the design of the schemes follows the well-established Fiat-Shamir paradigm, which should guarantee existential unforgeability, there are many side cases and encoding details that complicate the proofs, and all other security properties needed to be proven independently. Our work provides scientific rationale for choosing among several Ed25519 variants and understanding their properties, fills a much needed proof gap in modern protocol proofs that use these signatures, and supports further standardisation efforts. * We provide a summary of changes in Appendix C. Related Work History of EdDSA and Ed25519 Ed25519-Original is just one instantiation of the more general EdDSA signature scheme, which was introduced in the same paper [1], [6] . EdDSA is itself a variant of the well-known Schnorr signature scheme [20], [21] . Ed25519 is EdDSA instantiated over curve Edwards25519 [1] and remains by far the most popular instantiation of EdDSA, despite its later extension to support alternative curves [7], [22] . EdDSA instantiations such as Ed25519-Original can sign and verify signatures substantially faster than almost all other signatures schemes at similar security levels. For schemes that have comparable speeds, Ed25519-Original further provides considerably smaller signatures, producing 64-byte signatures and 32-byte public keys. Additionally, EdDSA is widely considered to provide better resistance to side-channel attacks than alternative schemes. However, the original papers [1], [6] contain no formal statements (and consequently, no actual proofs) of its security properties. By virtue of its outstanding performance with respect to efficiency and bandwidth, EdDSA was standardised by the IETF between 2015 and 2017 [7] . In 2019, EdDSA was proposed to also be adopted as part of NIST's Digital Signature Standard (DSS) [10], [11] . In early 2020, the public call for comments was closed [12] , but as of writing, no new version has appeared. G IMP-KOA CID,A (pp): 1 (pk, sk) ← -A(ch, st) 5 return V 2 (pk, com, ch, rsp) G IMP-PA CID,A (pp): 1 (pk, sk) $ ← -KGen(pp)
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- BUFFing signature schemes beyond unforgeability and the case of post-quantum signaturesCas Cremers, Samed Düzlü, Rune Fiedler, Marc Fischlin et al.S&P 2021 · 37 citations
- Formal verification of the PQXDH Post-Quantum key agreement protocol for end-to-end secure messagingKarthikeyan Bhargavan, Charlie Jacomme, Franziskus Kiefer, Rolfe SchmidtUSENIX Security 2024 · 27 citations
- Keeping Up with the KEMs: Stronger Security Notions for KEMs and Automated Analysis of KEM-based ProtocolsCas Cremers, Alexander Dax, Niklas MedingerCCS 2024 · 11 citations
- End-to-End Encrypted Zoom Meetings: Proving Security and Strengthening LivenessYevgeniy Dodis, Daniel Jost, Balachandar Kesavan, Antonio MarcedoneEUROCRYPT 2023 · 7 citations
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 2 citations
Builds on4
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- LadderLeak: Breaking ECDSA with Less than One Bit of Nonce LeakageDiego F. Aranha, Felipe Rodrigues Novaes, Akira Takahashi, Mehdi Tibouchi et al.CCS 2020 · 58 citations
- Downgrade Resilience in Key-Exchange ProtocolsKarthikeyan Bhargavan, Christina Brzuska, Cédric Fournet, Matthew Green et al.S&P 2016 · 54 citations
- Seems Legit: Automated Analysis of Subtle Attacks on Protocols that Use SignaturesDennis Jackson, Cas Cremers, Katriel Cohn-Gordon, Ralf SasseCCS 2019 · 53 citations
Related papers
- On the Security of the PKCS#1 v1.5 Signature SchemeTibor Jager, Saqib A. Kakvi, Alexander MayCCS 2018 · 19 citations
- Efficient Proofs of Possession for Legacy SignaturesAnna P. Y. Woo, Alex Ozdemir, Chad Sharp, Thomas Pornin et al.S&P 2025
- Security of Hedged Fiat-Shamir Signatures Under Fault AttacksDiego F. Aranha, Claudio Orlandi, Akira Takahashi, Greg ZaveruchaEUROCRYPT 2020 · 17 citations
- On the Provable Security of (EC)DSA SignaturesManuel Fersch, Eike Kiltz, Bertram PoetteringCCS 2016 · 55 citations
- Exclusive Ownership of Fiat-Shamir Signatures: ML-DSA, SQIsign, LESS, and MoreMichael Meyer, Patrick Struck, Maximiliane WeishäuplCRYPTO 2025 · 1 citation
