ciphergoth: (Default)
[personal profile] ciphergoth
For the three or so cryptographers on my friends list:

The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...

Date: 2007-03-16 08:56 am (UTC)
From: [identity profile] ciphergoth.livejournal.com
You may be interested to note that it's carefully engineered to give the same signature for a given message every time

although actually, I would not preserve that property in an implementation. The reduction is still pretty tight without it, and without it you can do most of the heavy lifting on signature generation in advance.

Profile

ciphergoth: (Default)
Paul Crowley

January 2025

S M T W T F S
   1234
5678 91011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 17th, 2026 11:58 am
Powered by Dreamwidth Studios