The Ristretto specification defines a way to do hash-to-curve. The hash-to-curve draft and other drafts (such as the one on OPRFs) recommend doing it using hashtobase+elligator2 as with Ed25519 instead. A forthcoming paper is going to propose a 3rd way. This is annoying.
-
-
The H2C draft is for hashing to a curve, not a quotient group. Just like Edwards H2C, Ristretto's hash to curve is Elligator twice with addition (with H2B undefined) resulting in an Ed point. The OPRF draft uses Edwards H2C as a drop-in for Ristretto H2C (-Clear should be -FFSTV)
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.