[Cryptography] Low-order points on secp256r1?

Ondrej Mikle ondrej.mikle at gmail.com
Fri Mar 30 21:27:03 EDT 2018


I'm reading the following paper: https://eprint.iacr.org/2018/298

In appendix A (page 14), it states, there is a point of order 5 on secp256r1.
How is that possible when secp256r1 curve group has prime order and the cofactor
is 1?

Regards,
  O. Mikle


More information about the cryptography mailing list