Symbol  Meaning  Relevance 

F,q,p  A finite field F of characteristic p and #F = q = p^m.  For prime fields, q = p; otherwise, q = p^m and m>1. 
E  Elliptic curve.  E is specified by an equation and a field F. 
n  Number of points on the elliptic curve E.  n = h * r, for h and r defined below. 
G  A primeorder subgroup of the points on E.  Destination group to which byte strings are encoded. 
r  Order of G.  r is a prime factor of n (usually, the largest such factor). 
h  Cofactor, h >= 1.  An integer satisfying n = h * r. 
E  Suites  Section 

NIST P256  P256_XMD:SHA256_SSWU_RO_ P256_XMD:SHA256_SSWU_NU_ 

NIST P384  P384_XMD:SHA384_SSWU_RO_ P384_XMD:SHA384_SSWU_NU_ 

NIST P521  P521_XMD:SHA512_SSWU_RO_ P521_XMD:SHA512_SSWU_NU_ 

curve25519  curve25519_XMD:SHA512_ELL2_RO_ curve25519_XMD:SHA512_ELL2_NU_ 

edwards25519  edwards25519_XMD:SHA512_ELL2_RO_ edwards25519_XMD:SHA512_ELL2_NU_ 

curve448  curve448_XOF:SHAKE256_ELL2_RO_ curve448_XOF:SHAKE256_ELL2_NU_ 

edwards448  edwards448_XOF:SHAKE256_ELL2_RO_ edwards448_XOF:SHAKE256_ELL2_NU_ 

secp256k1  secp256k1_XMD:SHA256_SSWU_RO_ secp256k1_XMD:SHA256_SSWU_NU_ 

BLS12381 G1  BLS12381G1_XMD:SHA256_SSWU_RO_ BLS12381G1_XMD:SHA256_SSWU_NU_ 

BLS12381 G2  BLS12381G2_XMD:SHA256_SSWU_RO_ BLS12381G2_XMD:SHA256_SSWU_NU_ 
