Compatible cofactor multiplication for Diffie-Hellmanprimitives
Burton S. Kaliski · Electronics Letters · 1998
Cofactor multiplication has recently been proposed as a technique for protecting Diffie-Hellman primitives against certain attacks. However, a Diffie-Hellman primitive protected with cofactor multiplication as initially described produces different keys when not under attack than its unprotected counterpart. A simple modification to cofactor multiplication is presented that overcomes this incompatibility.