[cryptography] What's the state of the art in factorization?

Paul Crowley paul at ciphergoth.org
Sat Apr 24 02:20:34 EDT 2010

James A. Donald wrote:
> If you want shorter signatures, the proposed scheme does not
> beat the Boneh, Lynn and Shacham proposal  "Short Signatures
> from the Weil Pairing", which the Chevallier-Mames  paper
> mentions and cites.

Sure, but that depends on the existence of GDH groups, which seems a 
little less conservative than the assumption that DDH is hard in Z*_p or 
in for example a NIST elliptic curve.
