[Cryptography] Crown Sterling debunked

Phillip Hallam-Baker phill at hallambaker.com
Tue Sep 24 10:14:02 EDT 2019


On Tue, Sep 24, 2019 at 1:49 AM Stephan Neuhaus <stephan.neuhaus at zhaw.ch>
wrote:

> Good writeup! I especially like the use of the work factor to estimate
> difficulty.
>
> Technical nitpick though: perhaps you should speak of the "modular
> integer and elliptic curve variants of Diffie-Hellman" instead of
> "discrete log and elliptic curve" because both are discrete logs.
>

Are they? I can see that breaking the discrete log is going to affect
elliptic curve DH. Or at least could do.

But the ECDH problem is multiplication of a point by a scalar x.y.P ==
y.x.P. How does a logarithm come into it? extracting the private key from a
public key would be solving the point division problem surely (x = x.P/P) ?

Not saying you are wrong, just interested in the reasoning here.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://www.metzdowd.com/pipermail/cryptography/attachments/20190924/a2824bb7/attachment.htm>


More information about the cryptography mailing list