-DH-A-EKE powered by @url{http://cr.yp.to/ecdh.html, Curve25519}
-and @url{http://ed25519.cr.yp.to/, Ed25519}
-@item Key derivation function for verifier generation
-@url{https://en.wikipedia.org/wiki/PBKDF2, PBKDF2} based on
-@url{https://en.wikipedia.org/wiki/SHA-2, SHA-512}
+ DH-A-EKE powered by @url{https://cr.yp.to/ecdh.html, Curve25519}
+ and @url{https://ed25519.cr.yp.to/, Ed25519}.
+@item DH elliptic-curve point encoding for public keys
+ @url{https://elligator.cr.yp.to/, Elligator}.
+@item Verifier password hashing algorithm
+ @url{https://crypto.stanford.edu/balloon/, Balloon hashing} based
+ on BLAKE2b-256.
+@item Encryptionless confidentiality preserving encoding
+ @url{http://people.csail.mit.edu/rivest/chaffing-980701.txt,
+ Chaffing-and-Winnowing} (two Poly1305 MACs for each bit of message)
+ over 128 bits of
+ @url{http://theory.lcs.mit.edu/~cis/pubs/rivest/fusion.ps,
+ All-Or-Nothing-Transformed} (based on
+ @url{http://cseweb.ucsd.edu/~mihir/papers/oaep.html, OAEP} using
+ ChaCha20 with BLAKE2b-256 based
+ @url{http://crypto.stanford.edu/~dabo/abstracts/saep.html, SAEP+}
+ checksums) data with 128-bits of feeded random.