At the Asiacrypt'96 Conference, Lenstra presented a DSA variant which offers some workload advantage for the signer. In this paper, we show some instances of it are not secure unless special care is taken.
Alexandre Massoud Alahi, Kathrin Grosse
Mathias Josef Payer, Fei Wang, Duo Xu, Xiangyu Zhang