Twisted Edwards Curves
Twisted Edwards curves are parameterized by and are of the form
These are usually represented by the Extended Twisted Edwards Coordinates of Hisil, Wong, Carter, and Dawson: points are represented in projective coordinates as with
(More details on Edwards curve models can be found in the curve25519_dalek
curve_models
documentation). The case is the untwisted case; the case provides the fastest formulas. Unless specified otherwise, we for ​.
When both and are nonsquare (which forces to be square), the curve is complete. In this case the four-torsion subgroup is cyclic, and we can write it explicitly as
These are the only points with ; the points with are 2-torsion.