ciphergoth: (Default)
[personal profile] ciphergoth
For the three or so cryptographers on my friends list:

The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...

Date: 2007-03-16 08:49 am (UTC)
From: [identity profile] ciphergoth.livejournal.com
An eprint note would be about right - it's a very straightforward result, really, the proof is practically identical to the corresponding proof about Schnorr in

http://citeseer.ist.psu.edu/ohta98concrete.html

I'll try to write it up when I have time, which might be a while. I'll also include the other observation I had, which was that if you have a hash function H' which maps the group onto itself, then your public key can be (g^x, H'(g^x)^x), which is a third shorter.

Profile

ciphergoth: (Default)
Paul Crowley

January 2025

S M T W T F S
   1234
5678 91011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 18th, 2026 03:20 am
Powered by Dreamwidth Studios