Re: [tor-dev] A threshold signature-based proposal for a shared RNG

2014-01-21 Thread Nicholas Hopper
On Mon, Jan 20, 2014 at 7:32 AM, Ian Goldberg wrote: >> > Then again, if *that* code is written, then just having each authority >> > operator run an instance of that code in the role of Nick, and having >> > everyone add their results, works fine if everyone is online. It's also >> > easy to che

Re: [tor-dev] A threshold signature-based proposal for a shared RNG

2014-01-20 Thread Ian Goldberg
On Fri, Jan 17, 2014 at 10:01:13PM -0600, Nicholas Hopper wrote: > > Yes: Nick (who would probably be the one writing the code anyway) > > generates the shares encrypted to keys generated by the authority > > operators, sends them to the authority operators, and forgets the > > intermediate results

Re: [tor-dev] A threshold signature-based proposal for a shared RNG

2014-01-17 Thread Nicholas Hopper
On Fri, Jan 10, 2014 at 1:07 PM, Ian Goldberg wrote: > On Fri, Jan 10, 2014 at 10:38:06AM -0600, Nicholas Hopper wrote: >> We'll need a hash function H that can output elements of the subgroup >> generated by B with unknown discrete logarithms. For Curve25519, it >> should work to compute H(x) by