Issues
- 0
Generalized fast subgroup checks and cofactor clearing for all pairing-friendly curves
#52 opened by mratsim - 1
keygen: explicitly allow application to specify salt
#48 opened by kwantam - 0
- 5
Formal specification, testing and verification
#47 opened by spitters - 9
Support blind variant
#37 opened by chris-wood - 27
- 20
aggregate signatures and subgroup validation
#33 opened by kwantam - 2
Bit security level < 128
#42 opened by veorq - 0
- 1
Ambiguity in Proof of possession scheme
#35 opened by dot-asm - 1
Signing infinite point
#34 opened by dot-asm - 1
clarify that octets_to_point should be injective?
#36 opened by kwantam - 4
broken links
#32 opened by kwantam - 7
- 8
- 10
Question: does `FastAggregateVerify` accept point of infinity PK (i.e., `SK=0`)?
#27 opened by hwwhww - 4
Backwards compatability of KeyGen
#28 opened by CarlBeek - 10
BLS v3 with hash-to-curve v7
#22 opened by CarlBeek - 2
- 21
KeyGen, weak keys, and interop
#25 opened by kwantam - 1
compression vs aggregation
#7 opened by kwantam - 1
remove indirection in section 2?
#3 opened by kwantam - 1
domain separation for KeyGen?
#2 opened by kwantam - 1
SK to PK function in API
#11 opened by CarlBeek - 10
Why SHA256 and not SHA3-256?
#10 opened by valerini - 0
Behaviour of `CoreAggregateVerify` and `FastAggregateVerify` with `length(PKs)==0`
#16 opened by CarlBeek - 1
Defining function arguments as arrays
#17 opened by CarlBeek - 3
Serialisation additional bits
#18 opened by kirk-baird - 1
optimizations: move to separate section?
#4 opened by kwantam - 2
- 0