> > * Schnorr identification requires that the prover implement both > arithmetic routines modulo the group order The GPS scheme (which is a simple Schnorr variant) avoids this but you need to choose a larger challenge. -- Johannes