Hacker News new | past | comments | ask | show | jobs | submit login

You don't need Elligator to make DH-EKE work - you can do it with old-fashioned DH. The property you need is roughly that D(E(g^a, pw), guess) has the same distribution regardless of whether pw == guess. If the group is Z_p and g generates the whole group, then E could be a pseudorandom permutation of [1,p-1].

The problem with ECDH here is that group elements aren't just numbers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: