+ DH-A-EKE powered by @url{http://cr.yp.to/ecdh.html, Curve25519}
+ and @url{http://ed25519.cr.yp.to/, Ed25519}.
+@item DH elliptic-curve point encoding for public keys
+ @url{http://elligator.cr.yp.to/, Elligator}.
+@item Verifier password hashing algorithm
+ @url{https://password-hashing.net/#argon2, Argon2d}.
+@item Encryptionless confidentiality preserving encoding
+ @url{http://people.csail.mit.edu/rivest/chaffing-980701.txt,
+ Chaffing-and-Winnowing} (two Poly1305 MACs for each bit of message)
+ over 128 bits of
+ @url{http://theory.lcs.mit.edu/~cis/pubs/rivest/fusion.ps,
+ All-Or-Nothing-Transformed} (based on
+ @url{http://cseweb.ucsd.edu/~mihir/papers/oaep.html, OAEP} using
+ Salsa20 with BLAKE2b-256 based
+ @url{http://crypto.stanford.edu/~dabo/abstracts/saep.html, SAEP+}
+ checksums) data with 128-bits of feeded random.