<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<item>
  <id>05264060</id>
  <dt>a</dt>
  <an>05264060</an>
  <augroup>
    <au>Bernstein, Daniel J.</au>
  </augroup>
  <ti>Proving tight security for Rabin-Williams signatures.</ti>
  <so>Smart, Nigel (ed.), Advances in cryptology -- EUROCRYPT 2008. 27th annual international conference on the theory and applications of cryptographic techniques, Istanbul, Turkey, April 13--17, 2008. Proceedings. Berlin: Springer (ISBN 978-3-540-78966-6/pbk). Lecture Notes in Computer Science 4965, 70-87 (2008).</so>
  <py>2008</py>
  <pu>Berlin: Springer</pu>
  <lagroup>
    <la>EN</la>
  </lagroup>
  <ccgroup>
  </ccgroup>
  <utgroup>
  </utgroup>
  <cigroup>
  </cigroup>
  <ligroup>
    <li>doi:10.1007/978-3-540-78967-3_5</li>
  </ligroup>
  <abgroup>
    <ab>Summary: This paper proves ``tight security in the random-oracle model relative to factorization'' for the lowest-cost signature systems available today: every hash-generic signature-forging attack can be converted, with negligible loss of efficiency and effectiveness, into an algorithm to factor the public key. The most surprising system is the ``fixed unstructured $B = 0$ Rabin-Williams'' system, which has a tight security proof despite hashing unrandomized messages.</ab>
    <rv></rv>
  </abgroup>
</item>