James A. Donald wrote:
If you want shorter signatures, the proposed scheme does not
beat the Boneh, Lynn and Shacham proposal  "Short Signatures
from the Weil Pairing", which the Chevallier-Mames  paper
mentions and cites.

Sure, but that depends on the existence of GDH groups, which seems a little less conservative than the assumption that DDH is hard in Z*_p or in for example a NIST elliptic curve.
--
  __
\/ o\ Paul Crowley
/\__/ www.ciphergoth.org
_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography

Reply via email to