Abstract
Cofactor multiplication has recently been proposed as a technique for protecting Diffie-Hellman primitives against certain attacks. However, a Diffie-Hellman primitive protected with cofactor multiplication as initially described produces different keys when not under attack than its unprotected counterpart. A simple modification to cofactor multiplication is presented that overcomes this incompatibility.

This publication has 3 references indexed in Scilit: