[curves] MQV

Watson Ladd watsonbladd at gmail.com
Wed May 14 14:44:38 PDT 2014


On Wed, May 14, 2014 at 2:38 PM, Robert Ransom <rransom.8774 at gmail.com> wrote:
> On 5/14/14, Trevor Perrin <trevp at trevp.net> wrote:
>> Anyone know what the best version of MQV is? (HMQV, FHMQV, CMQV, SMQV, TMQV,
>> ??)
[cut]
>
> I don't see a good reason to use Schnorr's identification protocol
> instead of DH authentication, even now that Schnorr's protocol is
> legal to use.

There is a reason: the Schnorr protocol involves a fixed base
exponentiation to a random exponent, while DH authentication involves
a variable base exponentiation to a fixed exponent. If you are willing
to burn ROM on a table with limited RAM and low CPU power, the Schnorr
protocol is more efficient on the prover side.

Sincerely,
Watson Ladd

>
>
> Robert Ransom
> _______________________________________________
> Curves mailing list
> Curves at moderncrypto.org
> https://moderncrypto.org/mailman/listinfo/curves



-- 
"Those who would give up Essential Liberty to purchase a little
Temporary Safety deserve neither  Liberty nor Safety."
-- Benjamin Franklin


More information about the Curves mailing list