On 23/04/2010 11:57, Paul Crowley wrote:
>>> [2] http://www.cs.umd.edu/~jkatz/papers/dh-sigs-full.pdf
>
> My preferred signature scheme is the second, DDH-based one in the
> linked paper, since it produces shorter signatures - are there any
> proposals which improve on that?
There is RSA or Rabin
On Fri, Apr 23, 2010 at 3:57 AM, Paul Crowley wrote:
>
> My preferred signature scheme is the second, DDH-based one in the linked
> paper, since it produces shorter signatures - are there any proposals which
> improve on that?
http://eprint.iacr.org/2007/019
Has one. Caveat lector.
Regards,
Zo
Jonathan Katz wrote:
[2] http://www.cs.umd.edu/~jkatz/papers/dh-sigs-full.pdf
On the other hand, there is one published scheme that gives a slight
improvement to our paper (it has fewer on-line computations): it is a
paper by Chevallier-Mames in Crypto 2005 titled "An Efficient CDH-Based
Sig