Re: Curve25519-based EC-KCDSA



David Wagner wrote:
Huh. That does seem like a good question. I haven't the foggiest;
I can't see how hash(m,Y) could be any worse than hash(m) xor hash(Y),
either. Perhaps it's worth emailing the authors of ECDSA?

To avoid confusion, he's not talking about X9.63 EC-DSA. They're
talking about the Korean DSA algo [K == Korean right?].

http://grouper.ieee.org/groups/1363/P1363a/contributions/kcdsa1363.pdf

Tom

.