The sub-group hiding assumption is a computational hardness assumption used in elliptic curve cryptography and pairing-based cryptography.

It was first introduced in [1] to build a 2-DNF homomorphic encryption scheme.

