On 08/11/10 15:51, Jonathan Katz wrote:
I am looking for a short signature scheme (certainly shorter than RSA
signatures, as short as possible would be nice...) that is *patent-free*
and (less important) easy to implement. Any suggestions?
I'm surprised you're not choosing the DDH scheme proposed by Eu-Jin Goh,
Stanislaw Jarecki, Nan Wang and yourself:
http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.81.8245
AFAIK the the shortest signatures are 2k bits long (where roughly 2^k
operations are needed to break the scheme) and this is 3k bits. I know
of no patent-free short-signature schemes with better reductions.
--
__
\/ o\ Paul Crowley, [email protected]
/\__/ http://www.ciphergoth.org/
_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography