> http://eprint.iacr.org/2013/338.pdf
Isn't this straight from the crypto paper construction kit? Make up some criterion, show that a popular primitive or implementation lacks it, demonstrate that a new construction has it. Talk about the "standard model". Do not provide any explicit bounds. _______________________________________________ cryptography mailing list cryptography@randombit.net http://lists.randombit.net/mailman/listinfo/cryptography