Pieter Wuille [ARCHIVE] on Nostr: 📅 Original date posted:2018-07-08 📝 Original message:On Sun, Jul 8, 2018, 19:23 ...
📅 Original date posted:2018-07-08
📝 Original message:On Sun, Jul 8, 2018, 19:23 Erik Aronesty via bitcoin-dev <
bitcoin-dev at lists.linuxfoundation.org> wrote:
> Pretty sure these non interactive sigs are more secure.
>
Schnorr signatures are provably secure in the random oracle model assuming
the discrete logarithm problem is hard in the used group.
What does "more secure" mean? Is your construction secure with weaker
assumptions?
--
Pieter
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180708/4f9bcb27/attachment.html>
📝 Original message:On Sun, Jul 8, 2018, 19:23 Erik Aronesty via bitcoin-dev <
bitcoin-dev at lists.linuxfoundation.org> wrote:
> Pretty sure these non interactive sigs are more secure.
>
Schnorr signatures are provably secure in the random oracle model assuming
the discrete logarithm problem is hard in the used group.
What does "more secure" mean? Is your construction secure with weaker
assumptions?
--
Pieter
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20180708/4f9bcb27/attachment.html>