password-authentication crypto primitives for "Password authentication", described in https://hackmd.io/G_b2SsCDRTy7BycolApz9Q?both