>> Converting this simple protocol to the active case is harder than >> expected, and I'm working on it right now. > > Great, I'm looking forward to it! :-) >
Well, if you have a lot of spare time you can start some preprocessing :) In particular, I guess that the active protocol will almost surely need some commitment schemes. And to make them as efficient as we can, we will probably use some elliptic curves over Zp with p around 160 bits. Isn't it cool that 160bits is at the same time the size we need for security AND to avoid the overflows in the computation? :) Claudio _______________________________________________ viff-devel mailing list (http://viff.dk/) viff-devel@viff.dk http://lists.viff.dk/listinfo.cgi/viff-devel-viff.dk