| Name | Implementation Support | IPR Policy | Specification | Standardization (Body, Process) | Recognition by government authorities (NIST, BSI, ...) | Performance | Hardware support | Unlinkability-Uncorrelatability-Blind signatures possible | Security strength | Post-quantum security |
|---|---|---|---|---|---|---|---|---|---|---|
DIF (intention to transfer to IRTF CFRG) | * | 381 bit curve | ||||||||
barely | DIF (intention to transfer to IRTF CFRG) | * | ||||||||
Hyperledger Ursa, https://github.com/privacybydesign/gabi | CL-Signatures of there own do not have a formal specification, that is included in Anoncreds | none | * | Ursa: up to 7 seconds for a validation and approximately 30 seconds for credential definition generation; IRMA (Yivi): both in less than a second | equivalent to RSA2048 | |||||
Apache License 2.0 | different curves-different specs | different curves-different standards | * | high | ||||||
many mature implementations | X9.62-2005 | ANSI | 256 / 384 / 512 bit | |||||||
many mature implementations | * | high | 257 / 384 / 512 bit | |||||||
NIST | * | high | ||||||||
Hyperledger Anoncreds, https://github.com/hyperledger/anoncreds-v2-rs | PS-Signatures of there own do not have a formal specification, that is included in Anoncreds-V2 | none | * | medium, faster than CL, slower than Schnorr, single-digit milliseconds for all operations, even in a threshold decentralized setting | ||||||
many mature implementations | * | 2048 / 3072 / 4096 (scales bad) | ||||||||
many mature implementations | patents expired | different curves-different specs | different curves-different standards | * | high |