A new type of digital signature scheme whose security is based on the difficulty of solving systems of k polynomial equations in m unknowns modulo a composite n is proposed. The scheme uses a simple technique (called sequential linearization) for embedding trapdoors into such systems of equations.
展开▼