>> Converting this simple protocol to the active case is harder than
>> expected, and I'm working on it right now.
> Great, I'm looking forward to it! :-)

Well, if you have a lot of spare time you can start some preprocessing :)
In particular, I guess that the active protocol will almost surely
need some commitment schemes. And to make them as efficient as we can,
we will probably use some elliptic curves over Zp with p around 160
Isn't it cool that 160bits is at the same time the size we need for
security AND to avoid the overflows in the computation? :)

viff-devel mailing list (http://viff.dk/)

Reply via email to