[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Cryptography] Low-order points on secp256r1?

I'm reading the following paper: https://eprint.iacr.org/2018/298

In appendix A (page 14), it states, there is a point of order 5 on secp256r1.
How is that possible when secp256r1 curve group has prime order and the cofactor
is 1?

  O. Mikle
The cryptography mailing list
cryptography AT metzdowd.com