A Note on Cryptanalysis of the Preliminary Version of the NTRU Signature Scheme
暂无分享,去创建一个
In this paper a preliminary version of the NTRU signature scheme is cryptanalyzed. The attack exploits a correlation between some bits of a signature and coefficients of a secret random polynomial. The attack does not apply to the next version of the signature scheme.
[1] J. Hoffstein,et al. NSS : The NTRU Signature Scheme , 2000 .