Gilboa's semi-honest protocol (Crypto'99), but has a high-level of security against malicious
adversaries without further compilation. The achieved security suffices for many
applications, and, assuming DDH, can be cheaply compiled into full security.