|
|
|
|
|
by qrmn
3933 days ago
|
|
Of course, the Elligator and related mappings allow for (a subset of) valid curve points to be mapped to indistinguishable bit strings, which is very handy in some protocols. A backdoor merchant using Elligator 2, or Elligator Squared, in this particular setup wouldn't be detectable. |
|
Code at https://github.com/secYOUre/rsaelligatorbd