D. J. Bernstein
Authenticators and signatures

A state-of-the-art public-key signature system


Secret keys; public keys
The constant c
Signatures; verification
Standard signatures; signing
Expanded signatures
Compressed signatures




[rwtight] (PDF) 18pp. D. J. Bernstein. Proving tight security for Rabin-Williams signatures. Document ID: c30057d690a8fb42af6a5172b5da9006. URL: https://cr.yp.to/papers.html#rwtight. Date: 2008.02.01. Supersedes: (PDF) (PS) (DVI) 2003.09.26. (PDF) 2007.02.20. (PDF) 2007.10.07.

[rwsota] (PDF) 11pp. D. J. Bernstein. RSA signatures and Rabin-Williams signatures: the state of the art. Document ID: 5e92b45abdf8abc4e55ea02607400599. URL: https://cr.yp.to/papers.html#rwsota. Date: 2008.01.31.

[sigs] 11pp. (retypeset PDF) (type-3 PDF) (PS) (DVI) D. J. Bernstein. A secure public-key signature system with extremely fast verification. URL: https://cr.yp.to/papers.html#sigs. Date: 2000.08.09. (This is mostly of historical interest now; it discusses an earlier design of the signature system.)

This signature system is discussed on the sigs mailing list.

An old version of the software, for an earlier design of the signature system, is sigs-0.50.tar.gz.

Relevant talks: