10-20s proving time is more than fast enough for me.
I'm going to dig through the gadgetlibs to get a feel for what it'd take to
implement this, but it's been a long time since my last algebra class.
On Wed, Jan 3, 2018 at 3:06 PM Andrew Miller wrote:
> Yeah! It's 2018
This is about the point where my math and libsnark knowledge runs out :)
My usecase is specifically cryptocurrency related, so I'm mostly interested
in curves that are used by cryptocurrency signature algorithms. E.g.
secp256k1 (Bitcoin and its kids), ed25519 (Sia, Stellar, and a few others).
Thank you so much for expressing your question in Camenisch-Stadler
notation! That makes it very clear what you're going for.
What hash function H do you have in mind, would SHA2 work? Also what group
G do you have in mind, secp256k1?
If so, I do not know of any existing implementation of