Last updated 1 year ago
Implementation using RSA.
Blinding.
Random blinding factor KKK.
k∗k−1≡1(modn)k * k^{-1} \equiv 1 (modn)k∗k−1≡1(modn)
m′=ke∗mmodNm' = k^e * m mod Nm′=ke∗mmodN
Ordinary signature (encryption w/ private key).
Ax(m′)=(m′)dmodNA_x(m') = (m')^d modNAx(m′)=(m′)dmodN
Unblinding
Ax(m)=k−1∗Ax(m′)modA_x(m) = k^{-1}*A_x(m')modAx(m)=k−1∗Ax(m′)mod