Cma H3Expected Loss le query Bounds
FiatShamir.Stateful.cmaH3ExpectedLoss_le_queryBounds
Plain-language statement
Expected H3 loss from direct signing and hash query bounds. If the adversary makes at most qS signing queries and at most qH random oracle queries, the accumulated state-dependent signing slack is bounded by the standard qS * ζ + qS * (qS + qH) * β expression.
Source project: VCVio
Person-level attribution pending.