Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a25e2f5d3ba85b65

Jump to content

Talk:NTRUSign

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia
Latest comment: 14 years ago by Ilya.kuzovkin in topic minimum number of signatures

minimum number of signatures

[edit]

2 MarioS Here is quote from the original article "The minimal number of signatures to make the attack successful in our experiments was 90,000, in which case the required number of random descents to run was about 400.". Therefore 400 is not number of signatures, the 90000 is.

Ilya.kuzovkin (talk) 13:01, 19 June 2012 (UTC)Reply

you quote from the section "Without exploiting the symmetries of NTRU lattices". in the section "Exploiting the symmetries of NTRU lattices" (on the same page), the authors write "as few as 400 signatures are enough in practice to recover the secret key, though the corresponding 100,400 parallelepiped samples are not independent. This means that the previous number of 90,000 signatures required by the attack can be roughly divided by N = 251." --MarioS (talk) 09:52, 20 June 2012 (UTC)Reply
True, You are right. The version of the paper I have somehow does not have this section. Ilya.kuzovkin (talk) 10:43, 20 June 2012 (UTC)Reply