Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
As pointed out by Danny Niu: "Note that for the P-521 instance, 521 bits are needed". #2 If Hedged ECDSA is used with P-521 and SHAKE, step h would need to be repeated several times, i.e., several KMAC invocations. The new text optimizes the use of KMAC.
- Loading branch information