James A. Donald wrote:
If you want shorter signatures, the proposed scheme does not beat the Boneh, Lynn and Shacham proposal "Short Signatures from the Weil Pairing", which the Chevallier-Mames paper mentions and cites.
Sure, but that depends on the existence of GDH groups, which seems a little less conservative than the assumption that DDH is hard in Z*_p or in for example a NIST elliptic curve.
-- __ \/ o\ Paul Crowley /\__/ www.ciphergoth.org _______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
