D. J. Bernstein
Authenticators and signatures

A state-of-the-art public-key signature system

Specification

Secret keys; public keys
The constant c
Signatures; verification
Hashing
Standard signatures; signing
Expanded signatures
Compressed signatures
Credits

Security

Cryptanalysis

Papers

[rwtight] (PDF) 18pp. D. J. Bernstein. Proving tight security for Rabin-Williams signatures. Document ID: c30057d690a8fb42af6a5172b5da9006. URL: https://cr.yp.to/papers.html#rwtight. Date: 2008.02.01. Supersedes: (PDF) (PS) (DVI) 2003.09.26. (PDF) 2007.02.20. (PDF) 2007.10.07.

[rwsota] (PDF) 11pp. D. J. Bernstein. RSA signatures and Rabin-Williams signatures: the state of the art. Document ID: 5e92b45abdf8abc4e55ea02607400599. URL: https://cr.yp.to/papers.html#rwsota. Date: 2008.01.31.

[sigs] 11pp. (retypeset PDF) (type-3 PDF) (PS) (DVI) D. J. Bernstein. A secure public-key signature system with extremely fast verification. URL: https://cr.yp.to/papers.html#sigs. Date: 2000.08.09. (This is mostly of historical interest now; it discusses an earlier design of the signature system.)


This signature system is discussed on the sigs mailing list.

An old version of the software, for an earlier design of the signature system, is sigs-0.50.tar.gz.

Relevant talks: