The Doppio Group

(This is a work in progress).

This site will describe the construction of a group called "Doppio", designed to provide a prime-order group for use inside of a Bulletproof. Doppio uses the Decaf construction on a curve defined over the ristretto255 scalar field and also serves as a worked example of how to use Decaf with elliptic curves embedded in zero-knowledge proof systems.

The curve selection procedure is described on this page.