
Composite order ECC and Ristretto

pk flag

I've been looking at, and its really cool.

I understand for some protocols we need curve points to behave as if they were from a prime order curve.

I have a few questions on this,

  1. Do we call curves without prime order "composite"?
  2. Why do some protocols demand prime order from the underlying curve?
  3. Why isn't the fact that we work inside a prime order subgroup anyway good enough in the first place, is it that the curve arithmetic is done over the entire curve?

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.