+Selection of Curves
+===================
+
+Note that the ciphertext contains elements in $G_1$ as well as $G_t$
+and therefore we need to be able to serialize them in a way that is
+(computationally) indistinguishable from random. As per Shermans
+comment and reference to https://ia.cr/2015/247