Security reductions
Mar. 15th, 2007 07:24 amFor the three or so cryptographers on my friends list:
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
no subject
Date: 2007-03-16 08:56 am (UTC)although actually, I would not preserve that property in an implementation. The reduction is still pretty tight without it, and without it you can do most of the heavy lifting on signature generation in advance.