with average-case/worst-case reductions

For signature schemes based on the Fiat-Shamir transformations, see [[Identification]].

Implementations

Extensions

Ring Signatures

Blind Signature

Group Signature and more

GGH

Proposal

Attacks

NTRU (NSS, R-NSS, NTRUSign)

Proposal

Attacks