3 ms·
If a single point matches the curve equation of a well-known curve then that’s pretty compelling evidence.
by nmadden 2y ago
If a single point matches the curve equation of a well-known curve then that’s pretty compelling evidence.
- Retr0id 2y agonot for compressed point representations (hence "depending on format")
- nmadden 2y agoSo just X25519 then?
- Retr0id 2y agoNo, most curves support a compressed (x coord, parity/sign bit) representation. It's what you'd probably be using if Elligator didn't exist, so makes sense as the point of comparison. https://datatracker.ietf.org/doc/draft-mattsson-tls-compact-ecc/ https://datatracker.ietf.org/doc/draft-mattsson-tls-compact-...
- kientuong114 2y agoThe point is that any random byte string can be decoded by Elligator to become a point matching the curve equation. This means that such a check is virtually useless and tells you nothing about whether there is a hidden key exchange happening or not.