Cryptanalysis of Nyberg-Rueppel's message recovery scheme

Chen-Ch Lin, Chi‐Sung Laih · IEEE Communications Letters · 2000

The standard drafts, P1363 (1996) and ISO 9796-4 (1998), have adopted the discrete-logarithm based on signature equation, S3, which was originally proposed by Nyberg and Rueppel (1994). They also claimed that the signature scheme based on S3 and S5 can resist the known message attack. In this letter, we propose an extended known message attack to show that the message recovery signature scheme based on S3 and S5 has the security problem.

Read the paper · More papers on PaperTik