Skip to content

Justify indifferentiability of mapHashOutputsToCurve from an RO wrt the hash_to_field outputs #25

Description

@daira

That is, prove the concrete indifferentiability relation $\mathsf{mapHashOutputsToCurve} \circ \mathsf{hash\_to\_field}(·, 2) {\large ⊏}_c \mathsf{hash\_to\_field}(·, 2)$, where $\mathsf{hash\_to\_field}(·, 2) ⦂ \mathcal{D} \rightarrow (\mathbb{F}_{q_{\mathbb{G}}})^2$ for $\mathcal{D}$ a suitable input type (domain separator and byte sequence), and $\mathsf{mapHashOutputsToCurve}$ as formalized in #19. This follows Brier et al.'s Theorem 1; it will require the form of the Weil bound defined in Curves.Hashing.WellDistributed as a named hypothesis, and consume TwoTermUniformity as the regularity half.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions