Opaque
Opaque copied to clipboard
Use Curve25519 for the Cyclic Group of Prime Order
The base point x=9 gives a cyclic group of prime order. This solves the issue of the parameter choice in secp256r1.
In fact it's what Ristretto does (give a group of prime order): https://libsodium.gitbook.io/doc/advanced/point-arithmetic/ristretto