On the Big Gap Between |p| and |q| in DSA.

Zhengjun Cao · 2007

Abstract We introduce a message attack against DSA and show that the security of DSA is indeed reduced to the following problem, i.e., find θ ∈ Z ∗ q such that z = (ˆg θ mod p) mod q where Ordp(ˆg) = q and z ∈ Z ∗ q is randomly chosen by the adversary. Compared with the common key-only attack, i.e., find x ∈ Z ∗ q such that y = g x mod p the message attack is more effective because of the big gap between |p | (1024-bit) and |q | (160-bit). Keywords DSA, Schnorr’s signature, message attack.

Read the paper · More papers on PaperTik