1

Why is the Edwards curve (like Ed25519) preferred for digital signatures, while the Montgomery curve (like Curve25519) is preferred for Diffie-Hellman key exchange? Since both curves perform scalar multiplication efficiently, what specific properties make them more suitable for their respective cryptographic tasks? Additionally, are there any recent studies or results available on the cycle counts required for Edwards25519 point multiplication on microcontrollers? I’ve found several studies focusing on Montgomery curve implementations in microcontrollers, but many papers on Edwards are either pre-2020 or focus on CPUs rather than microcontrollers.

0 Answers0