Posts
/ #POST-211181
REDDIT
Any Practical Use of Menezes Qu Vanstone over Authenticated Diffie-Hellman
I was studying Menezes Qu Vanstone from Serious Cryptography 2nd Edition. Aumasson mentions MQV is elegant and more secure than Authenticated Diffie-Hellman.
You cannot break MQV just by leaking ephemeral secrets.
Even if a long-term key is compromised the previously established keys are safe since they were derived using ephemeral secrets.
It does \*not\* offer perfect forward secrecy (although both users can do a key confirmation step to mitigate that).
I was just wondering...are there any cases in real life where MQV is preferable in practice over Authenticated Diffie-Hellman?
I thank in advance for any responses!