[Taler] Blind Rabin

From: Jeff Burdges
Subject: [Taler] Blind Rabin
Date: Sun, 26 Jan 2020 19:26:39 -0500

I’ve now forgotten, but did we ever consider using blind Rabin signatures?

It's discussed is section 3.3 on page 7 of

It’s not exactly compatible with DJB’s Rabin-Williams signature variants from
well see page 2 for the beginning of that discussion.

I think these blind Rabin signatures should've the fastest verification for any 
blind signature scheme, but the signature size looks like at least twice that 
of RSA, which I think poses some problem for Taler, so probably not 
advantageous in practice, and they require more careful mathematics for 
security arguments.


