4 ms·
I’m lost early in the article - it reads like you’re publishing your private key? Now, let's build a one-time signature scheme that allows you to sign a one-bi
by snissn 4y ago
I’m lost early in the article - it reads like you’re publishing your private key?
Now, let's build a one-time signature scheme that allows you to sign a one-bit message:
Choose two random inputs, % and %,. These make up our secret key.
• Publish h(%) and h(x). This is our public
key.
To sign bit o, publish %; to sign bit 1, publish x.
- dandanua 4y ago1. You publish two pairs (0, h(x0)), (1, h(x1)). It's your public key. 2. You publish h(x0) if you want to sign 0. 3. You publish x0 if you want to verify it. Your public key is unusable after that.
- quesomaster9000 4y agoSomewhat, refer to https://en.wikipedia.org/wiki/Lamport_signature https://en.wikipedia.org/wiki/Lamport_signature as a starting point. The extension using Merkle trees shows that you can open all of the on-bits in a message, where your public key is the Merkle tree root and your signature is the N authentication paths for all the 1s in the message bitstream, the average signature size will be `n/2 * log2(n) * n` bits. Of course this is fragile and the same public key (merkle tree root) cannot be used to open multiple messages - hence each signature includes the next public key and thus requires knowledge of the sequence/state of the signer which is not ideal and why Lamport signatures aren't really practical.