Security reductions
Mar. 15th, 2007 07:24 amFor the three or so cryptographers on my friends list:
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
no subject
Date: 2007-03-15 09:34 am (UTC)no subject
Date: 2007-03-15 09:45 am (UTC)(no subject)
From:no subject
Date: 2007-03-15 01:08 pm (UTC)has a tight reduction to the hardness of DDH
Saucy!
no subject
Date: 2007-03-15 04:58 pm (UTC)(no subject)
From:(no subject)
From:no subject
Date: 2007-03-15 09:11 pm (UTC)no subject
Date: 2007-03-16 12:55 am (UTC)(no subject)
From:(no subject)
From:(no subject)
From:Saw this, and thought of you :)
Date: 2007-03-16 02:43 pm (UTC)http://blog.wired.com/27bstroke6/2007/03/cryptographer_s.html