1

Based on the Schnorr signature below: What is the suitable size of lamda to generate a secure key?

Schnorr signature

fgrieu
  • 140,762
  • 12
  • 307
  • 587
Shi Li
  • 13
  • 4
  • Since $\lambda$ appears only in $1^\lambda$ on input of key generation, and no relation is formally defined between that and $q$, that $1^\lambda$ mention in the quote is merely a display of technical jargon, and the question is not answerable in the exact form it's asked. Also, a stretch of imagination is required to see the 1989 Schnorr signature scheme (doi). In particular, in the original, the hash is to a set of size $≈\sqrt q$, smaller than $\mathbb Z_q$ . Related answer. – fgrieu Jan 05 '23 at 08:53

0 Answers0