Two parties who have never met share no secret, and the adversary of this section intends to keep it that way. She owns the channel between them. As an eavesdropper she records the two group elements they exchange and tries to distinguish the key they derive from a random string—a key she can distinguish is a key whose every later use leaks. As an active attacker she does better than listen: she intercepts each party’s contribution, substitutes her own, and runs one honest-looking session with each victim, so that both “secure channels” terminate at her desk and she reads and rewrites every message in transit—forging, as we shall prove, without violating any hardness assumption at all. And on a public ledger her seat is permanent: every note ciphertext is published for ever, and she may scan them all at leisure, holding each against every address she can enumerate. This section builds the machinery that denies her all three postures: the Diffie–Hellman protocol atop the exponentiation asymmetry of Section 2; the static/ephemeral taxonomy that turns an interactive exchange into a one-shot flow; the key-agreement scheme abstraction that the deployed code programs against; passive security, which we prove equal to the DDH advantage exactly; the man-in-the-middle attack and the three external mechanisms of authentication; the elliptic-curve instantiation with its validation duties; the hybrid composition with a key-derivation function and an AEAD; key privacy, which keeps a ciphertext silent about its recipient; and the deployed endpoint, shielded-note delivery as hybrid public-key encryption carried in band on the ledger.
The raw material is the asymmetry established in Section 2. In a cyclic group of order , the map
is a group isomorphism—it carries addition of exponents to multiplication of elements—that is cheap to evaluate, at group operations by repeated squaring, but believed infeasible to invert in the groups this volume uses: inverting it is precisely the discrete logarithm problem (Definition 2.2). Everything in this section depends only on the group structure and the hardness of certain problems in it, never on the presentation of the group; the reference instances are a large prime-order subgroup of and the elliptic-curve point groups of §7.6. Diffie and Hellman’s observation is that the asymmetry alone already lets two strangers manufacture a shared secret in public.
Fix public parameters with of order , known to all parties (and to the adversary).
Alice samples uniformly, computes , and sends to Bob.
Bob samples uniformly, computes , and sends to Alice.
Alice computes ; Bob computes .
The value is the shared secret; the transmitted elements and are the public shares (public keys), and the exponents and are the private keys, never sent.
In Construction 7.1 both parties compute the same group element, .
Unwinding the definitions,
where because integer multiplication is commutative, and exponents may be read modulo because has order . □
The shared secret is thus a well-defined function of the transcript : it can be computed by anyone who knows one of the two private keys, and—conjecturally—by no one who knows only the public shares. Making that conjecture precise, and seeing exactly how much it buys, is the business of §7.4. First, a structural precaution.
If has small subgroups, an adversary can exploit them: by substituting for a public share an element of small order she confines the victim’s computed secret to a small subgroup and learns the victim’s exponent modulo a small factor of —the Pohlig–Hellman leakage of Corollary 2.21 in protocol form. The remedy is the standing rule of Section 2: prefer of prime order . Then the only subgroups are and itself, every non-identity element is a generator, and no nontrivial confinement is possible. When the natural ambient group does not have prime order— has composite order —one works inside a prime-order subgroup and has each recipient validate incoming elements as members: check and before exponentiating. The elliptic-curve analogue of this validation appears in Remark 7.19.
Nothing in Construction 7.1 says how long a key pair lives, and the protocol changes character with the answer.
A Diffie–Hellman key pair is static (long-term) if it is generated once and reused across many sessions, typically published and bound to an identity; it is ephemeral if it is generated freshly for a single session and discarded immediately afterwards.
Three protocol shapes result, and all three matter to what follows.
Ephemeral–ephemeral (DHE). Both parties use fresh keys. Once and are erased, no one—the parties included—can recover : this is forward secrecy, the guarantee that a later compromise of all stored long-term state cannot decrypt recorded past sessions, because the only secrets that ever existed were the deleted ephemerals.
Static–ephemeral. The recipient Bob holds a static pair , with known in advance; Alice contributes a fresh ephemeral . The shared secret then requires no interaction from Bob at agreement time: Alice computes from the published , attaches , and sends everything in a single flow; Bob recovers whenever he next comes online. This is exactly the shape of hybrid encryption (§7.7) and of shielded-note delivery (§7.9): sender online once, recipient possibly offline, no round trip.
Static–static. Both keys are long-term, so is a fixed function of the two identities—the same in every session. There is no forward secrecy, and the never-varying secret must be combined with fresh per-session randomness (a nonce) before it may key any symmetric scheme; using it directly would reuse one key across all time.
The static–ephemeral case is the conceptual bridge from key exchange, an interactive protocol, to public-key encryption, a one-shot algorithm. A static public key functions exactly as an encryption public key: anyone can derive a secret shared with its owner by sending a single ephemeral share. The rest of the section develops that bridge until, by §7.9, it carries deployed traffic.
Deployed code does not manipulate exponents; it programs against an interface. We therefore package the non-interactive (static–ephemeral) pattern as a scheme with named algorithms, so that later constructions—and the deployed note-encryption machinery—can invoke key agreement without caring which group sits underneath.
A (non-interactive) key-agreement scheme over a public parameter set consists of a private-key space , a public-key space , a shared-secret space , and three algorithms:
, randomised, outputting a private key ;
, deterministic, mapping a private key to its public key ;
, deterministic, mapping one’s own private key and a counterparty’s public key to a shared secret .
Correctness demands that for all and all in the support of ,
| (1) |
Fix with of prime order . The scheme takes (or , to avoid the degenerate case whose public key is the identity), , and
Correctness is exactly Proposition 7.2: .
The Zcash note-encryption machinery programs against precisely this abstraction, with one generalisation: the deployed takes the base point as an explicit argument rather than fixing a protocol-wide generator, so that Sapling and Orchard derive keys over per-address diversified bases (protocol specification §“Key Agreement”; the zcash_note_encryption crate’s Domain trait’s ka_derive_public, ka_agree_enc, and ka_agree_dec operate on abstract associated types, and Orchard’s implementation of derive_public in the orchard crate receives the base as a parameter). Those bases are put to work in §7.9, and the address machinery that produces them is detailed in the Ironwood Guide (§“Diversified addresses”). What matters here is that the interface still invokes an abstract key agreement and never inspects the underlying group—which is why the same construction has transported across three groups, from Sprout’s Curve25519 to Sapling’s Jubjub to Orchard’s Pallas.
Any concrete scheme satisfying equation (1) can be swapped in without changing the surrounding logic: a prime-field group, an elliptic curve, or a post-quantum non-interactive key agreement such as the CSIDH group action. A key-encapsulation mechanism (KEM), by contrast, cannot satisfy the correctness equation at all: encapsulation requires the recipient’s public key before it can produce its ciphertext, so no counterparty-independent exists. The static–ephemeral one-flow pattern does generalise to any KEM—the encapsulation ciphertext plays the role of the ephemeral public key—but at the cost of changing the interface the surrounding logic programs against.
The weakest adversary is the eavesdropper: she reads the channel but does not alter it, and her entire view of an honest session is the transcript . Both formalisations of her task were laid down in §2.2. The computational problem is to produce the shared secret: writing for the success probability of in the CDH game of Definition 2.4,
The decisional problem is to distinguish from with advantage (Definition 2.5). The hierarchy was established in §2.3 (Theorems 2.7 and 2.8), together with the pairing-based separation of DDH from CDH (Example 2.9). The distinction is not pedantry. Hardness of CDH asserts only that the whole secret cannot be computed; keying a symmetric cipher requires that the secret be indistinguishable from a uniform group element, so that no individual bit or predicate of it leaks. The following classical break shows the gap is real in the most familiar group.
Take , the full multiplicative group, with generator . The Legendre symbol is efficiently computable by Euler’s criterion and is multiplicative (Math Guide, §“Quadratic residues and the Euler criterion”). A generator of is a nonsquare, so : the symbol of a public share reveals the parity of its exponent. The parities of and determine the parity of , hence is determined by the two observed symbols. The distinguisher computes the predicted symbol of the shared secret from , compares it with the symbol of the third component, and outputs “Diffie–Hellman” on a match. On a genuine triple the match is certain; on a random triple the third component’s symbol is an independent uniform sign, matching with probability . The distinguishing advantage is the constant —even though CDH in is believed hard. The CDH/DDH gap therefore needs no pairings; the oldest group in the subject exhibits it. The cure is the prime-order rule of Remark 7.3: in a subgroup of odd prime order , every element is a square (), the symbol is identically , and the leak vanishes. This is one of the two reasons—the other being Pohlig–Hellman—that DDH is only ever assumed in prime-order groups.
With the assumption in place, passive security is not merely implied by DDH; it is DDH, advantage for advantage. We state the game in the volume’s tradition and prove the identification.
For a key-agreement scheme over and an adversary , the game runs as follows.
The challenger samples independently and computes the transcript .
It sets , samples uniformly, draws a hidden bit , and sends the transcript together with .
The adversary outputs a bit .
The advantage is ; the scheme is passively secure if every PPT adversary’s advantage is negligible in .
For the scheme of Construction 7.6 with uniform on , every adversary satisfies
identically and with running time preserved exactly. Under the DDH assumption the shared secret of an honest ephemeral–ephemeral session is therefore pseudorandom given the transcript: a passive adversary learns nothing about it that she could not have guessed about a random group element.
The two games are the same game. In for , the transcript is with uniform and independent; the real key is ; and the uniform alternative is exactly for uniform independent , because is a bijection. The challenge is thus verbatim a sample of or according to —the DDH distinguishing game of Definition 2.5. The identity map converts each adversary into the other, so the advantages coincide and no running time is added. □
Every use of a Diffie–Hellman secret in this volume feeds it into a key-derivation function to produce a symmetric key. What should the group deliver to that function? Hardness of CDH guarantees the secret is hard to produce in full, but not that it lacks efficiently predictable structure: the Legendre leak of Remark 7.9 is exactly such structure. Hardness of DDH guarantees the secret is as good as a random group element (Theorem 7.11)—no predicate of it is efficiently computable from the transcript. In practice one often assumes only CDH and models the hash-based KDF as a random oracle: the derived key is then uniform unless the adversary queries the oracle at the hidden shared secret, a route made precise in Theorem 7.24. Either way the design goal is the same: a derived symmetric key indistinguishable from uniform, because that is the hypothesis every theorem of Section 6 consumes.
Passive security is the most the bare protocol can offer, and the gap between it and what a channel needs is best exhibited as a construction. The adversary now controls the wire.
An active adversary controlling the channel between Alice and Bob runs two independent Diffie–Hellman sessions, one with each victim. She samples and computes . When Alice sends intended for Bob, intercepts it and forwards to Bob in its place; when Bob replies , she intercepts it and forwards to Alice. Alice computes , which also computes as ; symmetrically Bob computes , which computes as .
After the attack of Definition 7.13, Alice and Bob each hold a secret they believe is shared with the other but is in fact shared with ; and , knowing both and , can decrypt, read, modify, and re-encrypt every subsequent message in each direction, transparently to both parties. No assumption on —not even ideal hardness of the discrete logarithm problem—prevents this.
Correctness of Diffie–Hellman (Proposition 7.2), applied once per session, gives agreement between Alice and on and between Bob and on . The adversary knows her own exponent and received both and , so she computes both secrets directly—no problem instance is ever inverted, which is why no hardness assumption is relevant. Neither victim verifies the origin of the group element they received; each transcript is a syntactically valid run of Construction 7.1, so nothing in either party’s view distinguishes the attacked execution from an honest one. With and in hand, decrypts traffic from Alice under , re-encrypts it under for Bob, and symmetrically in reverse, editing at will in between. □
The lesson deserves stating structurally: passive security concerns the secrecy of the shared secret; active security additionally requires the authenticity of the public shares. Confidentiality of a channel is worthless if the channel is established with the wrong party. The bare protocol (Construction 7.1) provides no authentication—nothing in or testifies to who sent it—so the remedy must bind each public share to its sender’s identity, letting the recipient reject a substituted share. Every such binding is external to the key exchange itself.
All deployed remedies fall into three families, each external to the bare exchange.
Signed Diffie–Hellman. Each party signs its ephemeral share with a long-term signing key whose verification key is certified—by a certificate authority (a third party whose signature on the key the parties already trust) or by trust-on-first-use (accepting the first key seen and rejecting later changes). The adversary of Proposition 7.14 cannot forge Alice’s signature on , so her substitution is rejected. Digital signatures are the subject of Section 8; this composition is the structure of authenticated TLS.
Static keys that are themselves authenticated. If Bob’s static public key reaches Alice authentically—a trusted directory, a pinned key—then a static–ephemeral exchange toward already authenticates Bob to Alice: only the holder of can complete it. Note the direction: this authenticates the recipient, not the sender. It is the model relevant to public-key encryption, and to shielded-note delivery, where the recipient’s address is an authenticated public key (§7.9).
Out-of-band verification. The parties compare a short fingerprint of the exchanged public keys over a channel that is authentic even if low-bandwidth—digits read aloud on a call, a QR code scanned in person.
In every case the key-agreement security goal remains the passive guarantee of Theorem 7.11; authentication is a separable layer composed around the exchange, not a property of the group operation.
The development so far is deliberately group-agnostic; we now instantiate it on the groups the deployed protocol actually uses. Recall from the Math Guide (§“Elliptic curves”) that an elliptic curve over a field of characteristic neither nor is given in short Weierstrass form with nonzero discriminant, and that its -rational points form a finite abelian group under chord-and-tangent addition with the point at infinity as identity (Math Guide, §“The group structure of ”). The group is written additively, so exponentiation becomes scalar multiplication , computable in point additions by double-and-add. Elliptic-curve Diffie–Hellman is the transliteration.
Fix an elliptic curve , a base point of large prime order generating , and cofactor . In the abstraction of Definition 7.5:
The shared secret of parties with private keys and is . The associated hard problems are the discrete-logarithm, CDH, and DDH definitions of Section 2 (Definitions 2.2, 2.4, and 2.5) read with in place of —the problems ECDLP (Math Guide, §“The elliptic-curve discrete logarithm problem”), ECCDH, and ECDDH of §2.6.
Scalar multiplication is cyclic-group exponentiation in additive dress: the group is abelian, and acts on through because , so for all integers . Hence , which is condition (1). □
Well-chosen elliptic-curve groups admit only the generic attacks of §2.4, whereas index calculus solves the discrete logarithm in in subexponential time (Remark 2.18); a -bit curve therefore delivers the security level that a multi-thousand-bit prime field requires (Example 2.17). That efficiency, together with the availability of curves engineered for cheap in-circuit arithmetic, is why the Pallas curve of §2.6 underlies Orchard.
A recipient computing on an attacker-supplied point must guard against two pitfalls, the elliptic-curve forms of the validation duty in Remark 7.3.
Invalid-curve attack. The received coordinates may satisfy not ’s equation but that of a different, weaker curve which shares the same addition formulas (the chord and tangent slopes of the Math Guide, §“Explicit affine formulas”, involve but never ); scalar multiplication then runs happily in the wrong group, whose order may be smooth. The implementation must check the curve equation on every incoming point.
Small-subgroup attack. When the cofactor , an adversary submits a point of small order dividing , confining to a tiny subgroup and learning modulo a small factor. The defences are cofactor clearing—multiply incoming points by —or choosing a curve with .
Prime-order curves such as Pallas sidestep the cofactor issue entirely: with there is no small subgroup to hit, and only the on-curve check remains. The deployed arithmetic enforces exactly that check at deserialisation, as documented in Proposition 2.27, whose compressed encoding cannot even represent a point off the curve.
Three obstacles separate the Diffie–Hellman shared group element from a usable encryption scheme. First, the shared secret is a structured group element—a curve point with coordinates satisfying an equation—not a uniform string of key bits. Second, the exchange by itself transports no message: it manufactures a secret, and stops. Third, we want the static–ephemeral non-interactive flow of §7.2, so that the recipient need not be online. All three are resolved by one composition: key agreement for the secret, a key-derivation function for uniformity, an authenticated cipher for the message—hybrid public-key encryption (HPKE). The two symmetric ingredients were built in Section 6; we recall them in the specialised shape the composition needs.
A key-derivation function here is a deterministic function
mapping input keying material together with a context string to an -bit key. This specialises Definition 6.24 (§6.6) by omitting the salt and fixing the output length . For Theorem 7.24 we model the function as a random oracle (§3.4): distinct inputs then have independent uniform outputs, and security follows provided the adversary never queries the oracle at the hidden Diffie–Hellman secret and context. This is a source-specific random-oracle guarantee, not a generic claim that a deterministic function extracts uniform bits from every high-min-entropy source.
An authenticated encryption scheme with associated data with key space —matching the KDF output—is a pair with and , where is a nonce, is associated data authenticated but not encrypted, and denotes rejection (Definition 6.13). Correctness: . Security is authenticated-encryption security (Definition 6.15): encryptions of any two equal-length messages are CPA-indistinguishable (Definition 6.4), and no adversary can produce a fresh ciphertext decrypting to anything but (ciphertext integrity, Definition 6.14)— confidentiality and integrity simultaneously.
Fix ECDH over of prime order (Construction 7.16, in the interface of Definition 7.5), a secure KDF, and a secure AEAD as above. The recipient holds a static key pair with published. To encrypt a message to :
sample an ephemeral and set ;
compute the shared secret ;
derive the symmetric key , where includes and the protocol’s labels;
output with for a fixed or derived nonce —fixed is safe because each is used once.
To decrypt with : compute , derive with read from the ciphertext, and output , which is on an honest ciphertext; on a tampered one, ciphertext integrity makes the output except with negligible probability. Anyone holding can encrypt; only the holder of can decrypt.
For every message and every honestly generated ciphertext of Construction 7.22, decryption returns .
Model the KDF as a random oracle (Definition 3.13) and let the AEAD be secure in the sense of Definition 6.15. Consider a passive adversary who sees the public key and a single challenge ciphertext: she names two equal-length messages , receives the encryption of for a hidden uniform bit , and guesses , with CPA advantage defined as in Definition 6.4. Under CDH in no PPT adversary has non-negligible advantage; concretely, if makes at most random-oracle queries, then
for explicit reductions against CDH and against the AEAD’s authenticated-encryption security (of which the proof consumes only the confidentiality half, so is the CPA advantage of Definition 6.4 read against the AEAD), each running in essentially the same time as .
The proof is a game hop.
Game 0 is the real CPA game: the challenge ciphertext is with , , , and . Say wins a game when her guess equals .
Game 1 replaces by an independent uniform -bit string, leaving everything else unchanged.
The hop. In the random oracle model the two games proceed identically unless the adversary queries the oracle at exactly the point : until that query, the oracle’s value there is a uniform string she has never seen, which is precisely what Game 1 hands out. But producing from the view is exactly solving CDH. The reduction embeds its CDH challenge as and simulates Game 1 around it: it draws and a uniform -bit key itself, encrypts under to form the challenge ciphertext, and implements the oracle by lazy sampling—a fresh uniform string for each new query, the stored answer on a repeated one, so that the oracle remains a consistent function. The simulation is a perfect run of Game 1, and the critical query occurs in it with the same probability as in Game 0, the two games being identical until it happens. One obstruction remains: in a pairing-free group cannot recognise which of the queries carries (Example 2.9 shows recognising it is the DDH-test a gap group would supply). So picks one of the at most queries uniformly at random and outputs its first component; whenever the critical query occurs, ’s choice is correct with probability at least . Hence
The factor is a genuine guessing-type security loss, in the tightness taxonomy of Definition 1.22. Assuming gap-CDH—CDH hardness even given a DDH-decision oracle, which would let test each query—restores tightness; we state the loose bound because it is what plain CDH buys, and honesty about the loss is part of the bound.
Game 1 analysed. The AEAD key is now uniform and independent of everything else in the adversary’s view, which is exactly the hypothesis of the AEAD’s confidentiality game. The reduction forwards to its AEAD challenger, embeds the returned ciphertext as alongside a self-generated , and relays ’s guess; the AEAD challenger’s hidden bit plays , so .
Accounting. The difference-form advantage of Definition 6.4 is twice the bit-guessing advantage of Definition 1.15, so the triangle inequality across the hop gives
the stated bound.
Alternative hypothesis. The random oracle can be traded away, but not for Definition 6.24 alone: that guarantee is stated for a uniform independent salt, which the specialised KDF of Definition 7.20 omits, and the definition denies any generic unsalted guarantee. The trade needs an explicit hypothesis on the deployed function—the narrower premise Definition 6.24 allows for unsalted use: for a uniform group element , the output is computationally indistinguishable from a uniform -bit string given the context. Under that hypothesis and DDH in place of CDH, Theorem 7.11 first replaces the shared secret by a uniform group element at cost , and the stated indistinguishability then replaces by a uniform string—no oracle and no factor, at the price of the stronger decisional assumption on the group and an explicit pseudorandomness assumption on the KDF. □
Dropping any piece of Construction 7.22 breaks the composition.
Without the KDF, one would key the cipher with the raw group element . Its bit-representation is non-uniform—curve points do not fill the encoding space—and in non-DDH groups it is partially predictable, the Legendre-symbol leakage of Remark 7.9 being the classical instance. The KDF standardises the format, extracts uniform bits, and, by folding into its context, ties the derived key to this particular ephemeral share.
Without AEAD integrity, a passively confidential but malleable cipher would let an active adversary tamper with undetectably—the XOR-malleability of Section 6’s stream ciphers is total. Ciphertext integrity (Definition 6.14) makes any modification decrypt to except with negligible probability, giving the symmetric payload its chosen-ciphertext robustness.
Without the ephemeral key—a static–static variant—every message to would begin from the same shared secret. The fresh per-message ephemeral, with bound into the KDF context, gives each ciphertext separate key material, so nothing relies on nonce uniqueness under a reused key. What it does not supply is forward secrecy against later compromise of the recipient’s static key : from a recorded , an attacker who learns recomputes and with it the ciphertext’s key. Erasing buys only the sender-side guarantee that the key derives from no stored secret of the sender.
Theorem 7.24 answers the eavesdropper and leaves the scanner untouched. Her posture is different: she holds a published ciphertext against every public key she can enumerate and asks not what it says but to whom. Confidentiality is silent on the question—a scheme may hide the message perfectly and still stamp the recipient’s key on every ciphertext. The property that denies her is key privacy, due to Bellare, Boldyreva, Desai, and Pointcheval. We state it for a generic public-key scheme, then prove it for the bare static–ephemeral flow with the message folded in—ElGamal encryption, the shape whose key privacy the upper volumes consume.
A public-key encryption scheme over consists of a randomised , a randomised , and a deterministic with for every key pair in the support of and every message . For an adversary the game runs as follows.
The challenger samples independently and sends .
The adversary outputs a message .
The challenger draws a hidden bit and sends .
The adversary outputs a bit .
The advantage is ; the scheme is key-private (IK-CPA) if every PPT adversary’s advantage is negligible in . The message is the adversary’s own, so nothing about it is hidden; what the game hides is the key.
Fix as in Construction 7.16, written additively, and take group elements as messages; write for the scheme. A key pair carries its own base : in the fixed-base variant ; in the per-key-base variant samples , the generalised interface of Remark 7.7.
: choose as above and ; output and with .
: sample ; output .
: output .
Correctness is the scalar identity in the proof of Proposition 7.17, valid for any base in : , so . The scheme is the static–ephemeral flow of §7.2 with the shared secret spent as a one-time pad on a group element; the fixed-base variant is ElGamal’s original scheme transposed from to a prime-order group.
For ElGamal over (Construction 7.27, either base variant), every adversary yields two distinguishers against DDH in (Definition 2.5, read with in place of as in Construction 7.16), each running in the time of plus one key generation and four scalar multiplications, with
Under the DDH assumption ElGamal is therefore IK-CPA: a ciphertext is computationally independent of the public key it was made for.
The proof is a hybrid through a game that uses no key at all. Write and for the IK-CPA game with fixed to and to , and for the probability that outputs in each, so that . Let be the game whose challenger, after the same key generation and the same message from , answers with for independent and uniform, and let be the corresponding probability. The challenge of is computed without reference to either key, and the triangle inequality reduces the claim to bounding each hop by a DDH advantage.
The hop . The distinguisher receives a triple with or uniform. It samples in the per-key-base variant and sets in the fixed-base variant, plants the challenge in key as
generates honestly, and hands the pair . For invertible the base is uniform on , and with uniform is an honest public key whose private key the distinguisher never learns—nor needs, the game offering no decryption. On receiving it replies with
and outputs ’s bit. If , then and , so is an honest encryption under key with ephemeral uniform: the view of is exactly . If is uniform, then is uniform in and independent of everything else because is invertible, and is uniform in and independent of everything else because generates and is independent of , of key , and of , which chose before seeing : the view is exactly . Hence .
The hop is the same with the challenge planted in key and key generated honestly, giving with . Each distinguisher performs one honest key generation and the four scalar multiplications beyond running . Summing the two hops gives the bound. □
The hybrid transfers verbatim to Construction 7.22: planting the challenge in the recipient’s key and the ephemeral share exactly as above makes the shared secret uniform, and once it is, the pair with is computed without reference to the recipient’s key—provided the KDF context names no recipient key, which it must not. The deployed KDF takes (§6.6): the shared secret is the keying material, the context is under a personalisation label, and no key of the recipient enters. The protocol specification requires the composed note-encryption scheme to be key-private (§“Key Derivation”): a chain scanner holding a note ciphertext against every address she can enumerate learns nothing about which one it was sent to. The second use is the group-element share of diversified-address unlinkability. A diversified address (Remark 7.30) is a per-key-base ElGamal public key, and a fresh address of the same over a new base has, when that base is modelled as a uniform group element, the distribution of an encryption of under that key; telling which of two authorities a third address belongs to is then the IK-CPA game, and Theorem 7.28 answers it. The protocol specification sets up that correspondence, modelling the group hash behind the base as a random oracle (§“ and Hash Functions”); the Wallet Guide states the resulting unlinkability requirement (§“Diversifier indices”).
The chain assembled in this section is not an analogy for what the deployed protocol does; it is the deployed protocol, run in band on the public ledger.
A shielded address embeds a static public key on the protocol’s curve (Pallas, in Orchard), where the private scalar is the recipient’s incoming viewing key. The base is not a protocol-wide generator but a per-address diversified base, the hash-to-curve image (§3.7) of the address’s diversifier—the generalised interface of Remark 7.7 exists precisely to accommodate it (DiversifiedTransmissionKey is derived as ); the Ironwood Guide develops the key hierarchy (§“Viewing keys”) and address encoding (§“Diversified addresses”) behind these bases. The sender runs Construction 7.22 over that base, with one deployed refinement: the ephemeral scalar is not sampled directly but derived by (Remark 5.14) from the note’s random seed (ZIP 212; RandomSeed::esk_inner applies PrfExpand::ORCHARD_ESK), so that the uniform-ephemeral hypothesis of Theorem 7.24 is met through the PRF’s pseudorandomness and the recipient can later re-derive from the delivered seed. The sender publishes in the transaction, derives
by the personalised BLAKE2b call of §6.6, and AEAD-encrypts the note plaintext—a version byte, the recipient’s diversifier, the value, the note’s random seed, and the memo—under with ChaCha20-Poly1305 (Construction 6.18), attaching the ciphertext to the transaction. The nonce is fixed to zero and the associated data is empty, safe because each keys exactly one encryption (protocol specification §“Encryption (Sapling and Orchard)”; the zcash_note_encryption crate’s encrypt_note_plaintext, which chains ka_agree_enc, kdf, and ChaCha20Poly1305 with the zero nonce; the Orchard instantiation of the Domain trait is in the orchard crate).
Chain scanners see in every shielded output, but lacking they learn nothing (Theorem 7.24); the recipient trial-decrypts, deriving for each incoming transaction and keeping those outputs whose AEAD tag verifies and whose plaintext passes two consistency checks: the note commitment recomputed from it must match the commitment on chain, and the re-derived from its random seed must reproduce the published —the notes addressed to them (protocol specification §“Decryption using an Incoming Viewing Key (Sapling and Orchard)”). Non-interactivity is essential, and it is exactly the static–ephemeral flow of §7.2: the recipient need never have been online when the note was sent. Authenticity of the static key—the concern of §7.5—is supplied by mechanism (2) of Remark 7.15: the address is part of the recipient’s verified payment credential, so the man-in-the-middle substitution has nowhere to stand; and, as noted there, this authenticates the recipient rather than the sender. The complementary guarantees on the note’s contents—that the value is well-formed and conserved, that the commitment on chain matches the plaintext delivered—come not from the encryption but from the accompanying zero-knowledge proof.
The primitive toolbox now covers the delivery of a secret to a party who was never online to negotiate it. What travels alongside that ciphertext—the authorising signatures over the transaction that carries it—is the business of the next section.