11. Riferimenti
11.1. Riferimenti normativi
[AR13] A. Adj., F. Rodriguez-Henriquez "Square Root Computation over Even Extension Fields", 2013, https://eprint.iacr.org/2013/522.
[BBJLP08] D. J. Bernstein, P. Birkner, M. Joye, T. Lange, C. Peters "Twisted Edwards Curves", 2008, https://eprint.iacr.org/2008/013.
[BHKL13] D. J. Bernstein, M. Hamburg, A. Krasnova, T. Lange "Elligator: Elliptic-curve points indistinguishable from uniform random strings", 2013, https://eprint.iacr.org/2013/325.
[BLS12-381] S. Bowe, "BLS12-381: New zk-SNARK Elliptic Curve Construction", 2017, https://electriccoin.co/blog/new-snark-curve.
[BL19] A. Brier, et al., "Indifferentiable Hashing to Barreto-Naehrig Curves", 2019, https://eprint.iacr.org/2019/1170.
[BP17] C. Budroni, F. Pintore "Efficient hash maps to G2 on BLS curves", 2017, https://eprint.iacr.org/2017/419.
[CDMP05] J. Coron, et al., "Merle-Damgard Revisited: How to Construct a Hash Function", 2005, https://eprint.iacr.org/2005/365.
[CK11] D. Charles, K. Lauter "A note on high-security hash functions and the NIST SHA-3 competition", 2011, https://eprint.iacr.org/2011/529.
[BCIMRT10] E. Brier, et al., "Efficient Indifferentiable Hashing into Ordinary Elliptic Curves", 2010, https://eprint.iacr.org/2010/1004.
[FFSTV13] F. Farashahi, P. A. Fouque, I. E. Shparlinski, M. Tibouchi, J. F. Voloch "Indifferentiable deterministic hashing to elliptic and hyperelliptic curves", 2013, https://eprint.iacr.org/2013/380.
[FIPS180-4] NIST, "Secure Hash Standard (SHS)", FIPS PUB 180-4, August 2015, https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf.
[FIPS186-4] NIST, "Digital Signature Standard (DSS)", FIPS PUB 186-4, July 2013, https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf.
[FIPS202] NIST, "SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions", FIPS PUB 202, August 2015, https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf.
[FKR11] L. Fuentes-Castañeda, E. Knapp, F. Rodriguez-Henriquez "Faster Hashing to G2", 2011, https://eprint.iacr.org/2011/257.
[H15] O. Hesse "Über die Wendepuncte der Curven dritter Ordnung", 1862 (rilevante per i mapping di curva).
[Icart09] T. Icart, "How to Hash into Elliptic Curves", 2009, https://eprint.iacr.org/2009/226.
[KR17] M. Kammerer, A. Renaud "Hashing into Jacobians of Hyperelliptic Curves", 2017, https://eprint.iacr.org/2017/1171.
[KR20] S. Kim, I. R. "Indifferentiable Hashing to G2 on BLS curves", 2020, https://eprint.iacr.org/2020/824.
[LBB19] Y. Lee, et al., "Indifferentiable Hashing to Ordinary Elliptic Curves with Cofactor 1 or 2", 2019, https://eprint.iacr.org/2019/698.
[MOV96] A. Menezes, P. van Oorschot, S. Vanstone, "Handbook of Applied Cryptography", 1996, https://cacr.uwaterloo.ca/hac/.
[MT98] M. Matsumoto, T. Nishimura "Mersenne Twister: A 623-dimensionally equidistributed uniform pseudo-random number generator", 1998.
[P20] T. Pornin "Efficient Intentional Hashing to Elliptic Curves by Elligator 2", 2020, https://eprint.iacr.org/2020/014.
[RFC2119] S. Bradner, "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997, https://www.rfc-editor.org/info/rfc2119.
[RFC2104] H. Krawczyk, M. Bellare, R. Canetti, "HMAC: Keyed-Hashing for Message Authentication", RFC 2104, February 1997, https://www.rfc-editor.org/info/rfc2104.
[RFC5869] H. Krawczyk, P. Eronen, "HMAC-based Extract-and-Expand Key Derivation Function (HKDF)", RFC 5869, May 2010, https://www.rfc-editor.org/info/rfc5869.
[RFC7748] A. Langley, M. Hamburg, S. Turner, "Elliptic Curves for Security", RFC 7748, January 2016, https://www.rfc-editor.org/info/rfc7748.
[RFC8017] K. Moriarty, B. Kaliski, J. Jonsson, A. Rusch, "PKCS #1: RSA Cryptography Specifications Version 2.2", RFC 8017, November 2016, https://www.rfc-editor.org/info/rfc8017.
[RFC8018] M. Moriarty, Ed., B. Kaliski, R. Housley, "PKCS #5: Password-Based Cryptography Specification Version 2.1", RFC 8018, January 2017, https://www.rfc-editor.org/info/rfc8018.
[RFC8174] B. Leiba, "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, May 2017, https://www.rfc-editor.org/info/rfc8174.
[RFC7914] S. Josefsson, "The scrypt Password-Based Key Derivation Function", RFC 7914, August 2016, https://www.rfc-editor.org/info/rfc7914.
[RFC9106] A. Biryukov, D. Dinu, D. Khovratovich, S. Josefsson, "Argon2 Memory-Hard Function for Password Hashing and Other Applications", RFC 9106, September 2021, https://www.rfc-editor.org/info/rfc9106.
[SAGE] "SageMath, the Sage Mathematics Software System", https://www.sagemath.org/.
[SBCDK09] S. Scott, et al., "Fast Hashing to G2 on Pairing-Friendly Curves", 2009, https://eprint.iacr.org/2008/530.
[SEC1] "Standards for Efficient Cryptography 1 (SEC1): Elliptic Curve Cryptography)", SEC 1, May 2009, https://www.secg.org/sec1-v2.pdf.
[SEC2] "SEC 2: Recommended Elliptic Curve Domain Parameters", SEC 2, January 2010, https://www.secg.org/sec2-v2.pdf.
[S05] R. Sakai, "ID-based Cryptography and Its Application", 2005.
[SW06] A. Shallue, C. van de Woestijne "Construction of rational points on elliptic curves over finite fields", 2006, https://eprint.iacr.org/2006/285.
[T14] M. Tibouchi "Elligator squared: Uniform points on elliptic curves of prime order as uniform random strings", 2014, https://eprint.iacr.org/2014/043.
[U07] L. Ulas "Rational points on certain elliptic curves over finite fields", 2007, https://arxiv.org/abs/0706.1448.
[W19] R. S. Wahby "SVDW and SWU functions for any curve", 2019, https://github.com/kwantam/bls12-381-hash/blob/master/derivation.py.
[WB19] R. S. Wahby, D. Boneh "Fast and simple constant-time hashing to the BLS12-381 elliptic curve", 2019, https://eprint.iacr.org/2019/403.
[W08] L. C. Washington, "Elliptic Curves: Number Theory and Cryptography", 2nd edition, 2008.
[hash2curve-repo] "hash_to_curve reference code repository", https://github.com/pairing-law/hash2curve-code.
11.2. Riferimenti informativi
[ADKR07] A. Aranha, et al., "Identity-based encryption from the Tate pairing", 2007.
[AFQTZ14] A. Aly, et al., "Some efficient hash functions over elliptic curves", 2014, https://eprint.iacr.org/2014/501.
[BBJLP08] D. J. Bernstein, P. Birkner, M. Joye, T. Lange, C. Peters "Twisted Edwards Curves", 2008, https://eprint.iacr.org/2008/013.
[BF01] D. Boneh, M. Franklin "Identity-based encryption from the Weil pairing", 2001, https://eprint.iacr.org/2001/090.
[BJ02] E. Brier, M. Joye "Fast Multiplication on Elliptic Curves through Isogenies", 2002, https://eprint.iacr.org/2002/040.
[BL20] G. Banegas, et al., "Twelfth Night - or what you will: hashing to elliptic curves", 2020, https://eprint.iacr.org/2020/1466.
[BLS01] D. Boneh, B. Lynn, H. Shacham "Short Signatures from the Weil Pairing", 2001, https://eprint.iacr.org/2001/080.
[BLS03] P. S. L. M. Barreto, et al., "Efficient Algorithms for Pairing-Based Cryptosystems", 2003.
[BN05] P. S. L. M. Barreto, M. Naehrig "Pairing-Friendly Elliptic Curves of Prime Order", 2005, https://eprint.iacr.org/2005/133.
[BMP00] V. Boyko, P. MacKenzie, S. Patel "Provably Secure Password-Authenticated Key Exchange Using Diffie-Hellman", 2000, https://eprint.iacr.org/2000/014.
[BM92] S. M. Bellovin, M. Merritt "Encrypted Key Exchange: Password-Based Protocols Secure Against Dictionary Attacks", 1992.
[BDPV08] G. Bertoni, et al., "Building sponge functions from cryptographic primitives", 2008, https://eprint.iacr.org/2008/278.
[Br99] J. Brown "Update on the BLS12-381 construction", 1999.
[CFADLNV05] H. Cohen, et al., "Handbook of Elliptic and Hyperelliptic Curve Cryptography", 2005.
[Err4730] "RFC Errata 4730", https://www.rfc-editor.org/errata/eid4730.
[FT10] P. A. Fouque, M. Tibouchi "Estimating the size of the image of deterministic hash functions to elliptic curves", 2010, https://eprint.iacr.org/2010/599.
[FT12] P. A. Fouque, M. Tibouchi "Indifferentiable hashing to Barreto-Naehrig curves", 2012, https://eprint.iacr.org/2012/539.
[H20] M. Hamburg "Decaf and Ristretto", 2020, https://eprint.iacr.org/2020/008.
[Icart09] T. Icart, "How to Hash into Elliptic Curves", 2009, https://eprint.iacr.org/2009/226.
[J96] D. P. Jablon "Strong Password-Only Authenticated Key Exchange", 1996, https://www.iniietf.org/-public/pam/old/pam-96/jablon.ps.
[KR17] M. Kammerer, A. Renaud "Hashing into Jacobians of Hyperelliptic Curves", 2017, https://eprint.iacr.org/2017/1171.
[LBB19] Y. Lee, et al., "Indifferentiable Hashing to Ordinary Elliptic Curves with Cofactor 1 or 2", 2019, https://eprint.iacr.org/2019/698.
[MRH04] U. M. Maurer, R. Renner, C. Holenstein "Indiffentiability, Impossibility Results on Reductions, and Applications to the Random Oracle Methodology", 2004, https://eprint.iacr.org/2004/453.
[MRV99] S. Micali, et al., "Verifiable Random Functions", 1999, https://people.csail.mit.edu/silvio/Selected%20Scientific%20Papers/Pseudo%20Randomness/Verifiable%20Random%20Functions.pdf.
[NR97] M. Naor, O. Reingold "Number-Theoretic Constructions of Efficient Pseudo-Random Functions", 1997, https://theory.lcs.mit.edu/rivest/naor-reingold.pdf.
[OKS00] K. Ohta, T. Okamoto, "On concrete security treatment of signatures derived from identification", 2000.
[p1363.2] "IEEE Standard Specification for Public-Key Cryptographic Techniques Based on Elliptic Curves", IEEE P1363.2 / D15, December 2004.
[p1363a] "IEEE Public-Key Cryptography", IEEE P1363a, 2004.
[ristretto255-decaf448] "The ristretto255 and decaf448 Groups", https://ristretto.group/.
[RSS11] T. Ristenpart, et al., "Security of Structured Designs and Mappings", 2011, https://eprint.iacr.org/2011/108.
[VR20] S. V. D. S. R. "Dragonblood: Analysing the Dragonfly Handshake of WPA3", 2020, https://wpa3.mathyvanhoef.com/.
[W09] R. S. Wahby, "Fast and simple constant-time hashing to the BLS12-381 elliptic curve", 2009 (manoscritto non pubblicato).
[WB19] R. S. Wahby, D. Boneh "Fast and simple constant-time hashing to the BLS12-381 elliptic curve", 2019, https://eprint.iacr.org/2019/403.