<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Brain Dumps on gtank writes here</title><link>http://blog.gtank.cc/tag/brain-dumps/</link><description>Recent content in Brain Dumps on gtank writes here</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 26 Mar 2020 20:06:25 +0000</lastBuildDate><atom:link href="http://blog.gtank.cc/tag/brain-dumps/index.xml" rel="self" type="application/rss+xml"/><item><title>Notes on anonymous credentials</title><link>http://blog.gtank.cc/notes-on-anonymous-credentials/</link><pubDate>Thu, 26 Mar 2020 20:06:25 +0000</pubDate><guid>http://blog.gtank.cc/notes-on-anonymous-credentials/</guid><description>&lt;p&gt;Best anonymous credentials that don&amp;rsquo;t use pairings:&lt;/p&gt;
&lt;p&gt;Single show, no attributes, symmetric issuer: Privacy Pass; uses VOPRFs&lt;/p&gt;
&lt;p&gt;Multi show, attributes, symmetric issuer: CMZ14 (original, &lt;a href="https://eprint.iacr.org/2013/516"&gt;https://eprint.iacr.org/2013/516&lt;/a&gt;)/CPZ19 (group element attribute variant, &lt;a href="https://eprint.iacr.org/2019/1416"&gt;https://eprint.iacr.org/2019/1416&lt;/a&gt;); uses &amp;ldquo;algebraic MACs&amp;rdquo; and categorically supercedes U-Prove&lt;/p&gt;
&lt;p&gt;Single show, attributes, publicly verifiable: Anonymous Credentials Light; uses an Abe signature variant&lt;/p&gt;
&lt;p&gt;For multi-show with attributes &lt;em&gt;and&lt;/em&gt; public verifiability, as far as I know you need to use pairings to get randomizable signatures. The best general credential of this type might still be the first real one, CL04 (&lt;a href="https://cs.brown.edu/people/alysyans/papers/cl04.pdf"&gt;https://cs.brown.edu/people/alysyans/papers/cl04.pdf&lt;/a&gt;) but probably now you&amp;rsquo;d instantiate it with Pointcheval-Sanders signatures (PS16, &lt;a href="https://eprint.iacr.org/2015/525"&gt;https://eprint.iacr.org/2015/525&lt;/a&gt; + PS18, &lt;a href="https://eprint.iacr.org/2017/1197"&gt;https://eprint.iacr.org/2017/1197&lt;/a&gt; tweaked for better proofs) which allows for constant-size credentials.&lt;/p&gt;</description></item><item><title>Notes on threshold signature schemes</title><link>http://blog.gtank.cc/notes-on-threshold-signatures/</link><pubDate>Fri, 18 Oct 2019 02:33:40 +0000</pubDate><guid>http://blog.gtank.cc/notes-on-threshold-signatures/</guid><description>&lt;p&gt;A threshold signature allows a subset &lt;em&gt;t&lt;/em&gt; of a group of &lt;em&gt;n&lt;/em&gt; possible signers to collectively produce a signature for the entire group. The simplest ones tend to use some &lt;a href="https://en.wikipedia.org/wiki/Distributed_key_generation"&gt;distributed key generation&lt;/a&gt; (&amp;ldquo;DKG&amp;rdquo;) based on &lt;a href="https://en.wikipedia.org/wiki/Verifiable_secret_sharing"&gt;verifiable secret sharing&lt;/a&gt; (&amp;ldquo;VSS&amp;rdquo;) to construct the keys and secret inputs to a &lt;a href="https://en.wikipedia.org/wiki/Schnorr_signature"&gt;Schnorr signature&lt;/a&gt; in a distributed manner. There have been a lot of these, and recalling all the Feldman-this and Pedersen-that gets confusing. The following seem to be the core papers in the field of discrete-log threshold signatures:&lt;/p&gt;</description></item></channel></rss>