Browse Source
The previous impl. was in breach of the following section: > Please note that when k is generated from T, the result of bits2int is > compared to q, not reduced modulo q. If the value is not between 1 and > q-1, the process loops. > Performing a simple modular reduction would induce biases that would be > detrimental to signature security.hk-custom-address
2 changed files with 26 additions and 7 deletions
Loading…
Reference in new issue