D. J. Bernstein
Authenticators and signatures
A state-of-the-art public-key signature system
Specification
Secret keys; public keys
The constant c
Signatures; verification
Hashing
Standard signatures; signing
Expanded signatures
Compressed signatures
Credits
Security
Cryptanalysis
Papers
[rwtight]
(PDF)
18pp.
D. J. Bernstein.
Proving tight security for Rabin-Williams signatures.
Document ID: c30057d690a8fb42af6a5172b5da9006.
URL: https://cr.yp.to/papers.html#rwtight.
Date: 2008.02.01.
Supersedes:
(PDF)
(PS)
(DVI)
2003.09.26.
(PDF)
2007.02.20.
(PDF)
2007.10.07.
[rwsota]
(PDF)
11pp.
D. J. Bernstein.
RSA signatures and Rabin-Williams signatures: the state of the art.
Document ID: 5e92b45abdf8abc4e55ea02607400599.
URL: https://cr.yp.to/papers.html#rwsota.
Date: 2008.01.31.
[sigs]
11pp.
(retypeset PDF)
(type-3 PDF)
(PS)
(DVI)
D. J. Bernstein.
A secure public-key signature system with extremely fast verification.
URL: https://cr.yp.to/papers.html#sigs.
Date: 2000.08.09.
(This is mostly of historical interest now;
it discusses an earlier design of the signature system.)
This signature system is discussed on the
sigs mailing list.
An old version of the software,
for an earlier design of the signature system,
is sigs-0.50.tar.gz.
Relevant talks:
- 1997.03.07,
``The world's fastest digital signature system.''
- 1997.03.17,
``The world's fastest digital signature system.''
- 1997.10.25,
``A secure digital signature system with verification ten times faster than RSA.''
- 2000.10.20 (slides and video available),
``Design and implementation of a public-key signature system.''
- 2001.06.13,
``The state of the art in RSA-type signatures.''
- 2003.04.24 (slides available),
``Compressing RSA keys and signatures.''
- 2003.11.08 (slides available),
``News from the Rabin-Williams front.''
- 2003.11.08 (slides available),
``More news from the Rabin-Williams front.''
- 2004.08.17 (slides available),
``Stop overestimating RSA bandwidth!''
- 2004.09.16 (slides available),
``A state-of-the-art public-key signature system.''
- 2005.11.06 (slides available),
``Compressing RSA/Rabin keys.''
- 2006.11.27 (slides available),
``Proving tight security for Rabin-Williams signatures.''
- 2007.02.07 (slides available),
``Proving tight security for Rabin-Williams signatures.''