[curves] Climbing the elliptic learning curve (was: Re: Finalizing XEdDSA)

Antonio Sanso asanso at adobe.com
Mon Jan 30 12:41:51 PST 2017


Thanks a lot Trevor,

this was a great write up.
One more question

On Nov 7, 2016, at 12:51 AM, Trevor Perrin <trevp at trevp.net<mailto:trevp at trevp.net>> wrote:

However, cofactor>1 can still have subtle and unexpected effects, e.g.
see security considerations about "equivalent" public keys in RFC
7748, which is relevant to the cofactor multiplication "cV" in
VXEdDSA, or including DH public keys into "AD" in Signal's (recently
published) X3DH [3].

may you shed some more light about this?
What is the algorithm to find and “equivalent” public key?

regards

antonio

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20170130/72ebd5be/attachment.html>


More information about the Curves mailing list