[cryptography] What's the state of the art in factorization?
Paul Crowley
paul at ciphergoth.org
Fri Apr 23 05:57:09 EDT 2010
Jonathan Katz wrote:
>>> [2] http://www.cs.umd.edu/~jkatz/papers/dh-sigs-full.pdf
> On the other hand, there is one published scheme that gives a slight
> improvement to our paper (it has fewer on-line computations): it is a
> paper by Chevallier-Mames in Crypto 2005 titled "An Efficient CDH-Based
> Signature Scheme with a Tight Security Reduction".
My preferred signature scheme is the second, DDH-based one in the linked
paper, since it produces shorter signatures - are there any proposals
which improve on that?
Incidentally, the paper doesn't note this but that second scheme has a
non-tight reduction to the discrete log problem in exactly the way that
Schnorr does.
--
__
\/ o\ Paul Crowley, paul at ciphergoth.org
/\__/ http://www.ciphergoth.org/
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com
More information about the cryptography
mailing list