How damaging are the bilinear Diffie-Helman assumptions needed by the pairing based cryptography here? It's simply that the curve involved must be huge or something? Are those costs and risks well understood?
Also, I'm curious about the scheme for sterilizing HIBE keys mentioned on page 9, sounds useful for air-gapped keys. Is there is reasonable way to do that but avoid the bilinear Diffie-Helman assumptions needed by pairing based cryptography? I could imagine doing that with a server that stores signed keys for each time interval, not sure if the server can be avoided though. Jeff
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Messaging mailing list [email protected] https://moderncrypto.org/mailman/listinfo/messaging
