At the Asiacrypt'96 Conference, Lenstra presented a DSA variant which offers some workload advantage for the signer. In this paper, we show some instances of it are not secure unless special care is taken.
Mathias Josef Payer, Fei Wang, Duo Xu, Xiangyu Zhang
Alexandre Massoud Alahi, Kathrin Grosse