[curves] MQV

Johannes Merkle johannes.merkle at secunet.com
Thu May 15 04:18:07 PDT 2014

> * Schnorr identification requires that the prover implement both
> arithmetic routines modulo the group order 

The GPS scheme (which is a simple Schnorr variant) avoids this but you need to choose a larger challenge.

More information about the Curves mailing list