Digital signatures with RSA and other public-key cryptosystems
Dorothy E. Denning · Communications of the ACM · 1984
Public-key signature systems can be vulnerable to attack if the protocols for signing messages allow a cryptanalyst to obtain signatures on arbitrary messages of the cryptanalyst's choice.This vulnerability is shown to arise from the homomorphic structure of publickey systems.A method of foiling the attack is described.