In this subsection we present our solution based on one-time signatures. First we will recall briefly the ideas behind one-time signatures and then detail our implementation.

Fabien A.P. Petitcolas, Computer Laboratory, University of Cambridge