[cryptography] ECIES (Elliptic Curve Integrated Encryption System)

Jeffrey Walton noloader at gmail.com
Tue Jan 8 18:28:16 EST 2013


On Fri, Nov 30, 2012 at 1:14 AM, Jeffrey Walton <noloader at gmail.com> wrote:
>
> I'm getting ready to move some code to elliptic curves, and I'd like
> to look at ECIES for an off the shelf solution. Is anyone aware of
> defects in Shoup's ECIES (Elliptic Curve Integrated Encryption
> System)?
>
> I know I'm going to need to change some parameters to meet security
> goals. For example, I will need AES-256 and HMAC-SHA256. But I don't
> believe it will introduce any negative interactions.
I found DHAES (DHIES) schemes were a bit better for both security and
efficiency. DHAES had weaker assumptions, and enjoyed a little more
efficiency due to a cofactor of 2 or 4.

Jeff



More information about the cryptography mailing list