Symmetric External Diffie–Hellman (SXDH)
Proposed by: Emerged c. 2004–2005 (Scott; Ballard–Green–de Medeiros–Monrose 2005); popularized by Groth–Sahai (2008)
Category: Pairing-based
Let e:G1×G2→GT be an asymmetric (“Type-3”) pairing over groups of prime order q, with no efficiently computable homomorphism between G1 and G2 in either direction.
Assumption. [[ddh]] holds in both G1 and G2:
(gi,gia,gib,giab)≈c(gi,gia,gib,gic)for i∈{1,2}.
This is consistent because the pairing can only compare an element of G1 against one of G2 — within a single source group no DDH test is available. Standard instantiation: BLS12-381, BN curves.
Best known attacks
Discrete log in G1, G2, or GT (finite-field NFS for GT). Quantum-broken via Shor.
Importance
- The most efficient instantiation of Groth–Sahai NIZK proofs (2008, >2000 citations).
- Structure-preserving signatures, anonymous credentials (Microsoft U-Prove-adjacent literature, BBS-style schemes), compact e-cash.
- Type-3 pairings under SXDH are the default setting of modern pairing implementations (BLS12-381 in Zcash, Ethereum).