EdDSA (Edwards-curve Digital Signature Algorithm) is a high-performance digital signature scheme based on twisted Edwards elliptic curves, standardised in RFC 8032. It provides deterministic signing—eliminating the random number generation vulnerabilities that afflicted earlier schemes like ECDSA—whilst offering strong security with compact key and signature sizes. The most widely deployed instantiation is Ed25519, which operates over Curve25519 and produces 64-byte signatures with 128-bit security. EdDSA is extensively used in secure communications protocols, blockchain systems, verifiable credentials, and decentralised identity frameworks.

Content

  • EdDSA was introduced by Bernstein, Duif, Lange, Schwabe, and Yang in 2011 as a response to the fragility of earlier signature schemes such as DSA and ECDSA, both of which require a fresh random nonce per signature. Nonce reuse in those schemes catastrophically leaks the private key—as demonstrated by the PlayStation 3 hack—whereas EdDSA derives its nonce deterministically from the private key and message, removing this attack surface entirely.
  • The mathematical foundation is a twisted Edwards curve, a form of elliptic curve offering efficient constant-time arithmetic that resists side-channel timing attacks. The Ed25519 variant operates over the 255-bit prime field defined by Curve25519, yielding 64-byte signatures and 32-byte keys. Signing and verification are exceptionally fast: on modern hardware, Ed25519 signing completes in roughly 50 microseconds and batch verification is even more efficient, making it highly suitable for high-throughput authentication scenarios.
  • EdDSA has achieved broad adoption across security-critical systems. It is mandatory in TLS 1.3 negotiation contexts, used as the default signing algorithm in OpenSSH, Signal Protocol, WireGuard, and DNSSEC DANE records. In the blockchain space, Solana, Cardano, and Stellar use Ed25519 as their primary transaction signing algorithm, and it underpins the W3C Decentralised Identifiers (DID) key material in many implementations.
  • With the advent of post-quantum cryptography standardisation, EdDSA’s role is under active reassessment. Whilst quantum computers running Shor’s algorithm would break Ed25519, the algorithm’s clean specification and implementation simplicity have made it the reference design against which post-quantum signature candidates such as CRYSTALS-Dilithium and SPHINCS+ are benchmarked. Hybrid schemes combining Ed25519 with a post-quantum algorithm are emerging as a migration path.