Open AndAlBo opened 9 months ago
This is a can of worms. Are you sure you want to keep that property?
Are you sure you want to keep that property?
I've spent several hours today looking for more research on it, and after that, I am leaning towards "No" =) It seems too specific, and I feel like most lightweight AEADs should be efficient in DSL.
Russ Housley:
It is definitely not clear from the definition that ZK-friendly AEADs are intended to be efficiently implemented in proofs. I also agree that the example provided is not satisfactory.