Signature Protocols for RSA and Other Public- Key Cryptosystems
Dorothy E. Denning · Purdue e-Pubs (Purdue University System) · 1982
Public-key signature systems can be vulnerable to attack if the protocols for signi_ng messages allow a cryptanalyst to obtain signatures on arldr'L'ry messages of tile cryptanalysL's choice.This vulnerability is shown to ur'i;~(~frum th0.homomorphic sLructure of public-key systems.A signature proloeol thill foils the ullack is described.Gif Ca.i.e