[curves] BN254 and SPEKE

Van Gegel torfone at ukr.net
Tue Sep 22 08:31:33 PDT 2020

Hello all!
I will use ATE pairing on BN254 for blind signatures.
Also my app needs SPEKE protocol for password authentication.
I saw that the BN254 curve is marked as unsafe on safecurves.cr.yp.to due some factors.
Can I safely use this curve also for the SPEKE with Q1 only and checking the point on the curve before mult?

Van Gegel.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/curves/attachments/20200922/3b3c6580/attachment.html>

More information about the Curves mailing list