AlTACKS ON SOME RSA SlGNATURES

Wiebren de Jonge, David Chaum · 1986

Two simple redundancy schemes are shown to be inadequate in securing RSA signatures against attacks based on multiplicative properties. The schemes generalize the requirement that each valid message starts or ends with a fixed number of zero bits. Even though only messages with proper redundancy are signed, forgers are able to construct signatures on messages of their choice.

Read the paper · More papers on PaperTik