And here's @Matthew_D_Green providing that reconciliation: http://blog.cryptographyengineering.com/2015/10/a-riddle-wrapped-in-curve.html And there's even a link to the original paper (in .PDF) http://eprint.iacr.org/2015/1018.pdf