Injective Encodings to Elliptic Curves

Provided by: International Association for Cryptologic Research
Topic: Security
Format: PDF
For a number of elliptic curve-based cryptographic protocols, it is useful and sometimes necessary to be able to encode a message (a bit string) as a point on an elliptic curve in such a way that the message can be efficiently and uniquely recovered from the point. This is for example the case if one wants to instantiate CPA-secure ElGamal encryption directly in the group of points of an elliptic curve. More practically relevant settings include lindell's UC commitment scheme (EUROCRYPT 2011) or structure-preserving primitives.

