The Security of a Family of Two-Party RSA signature schemes
Mihir Bellare, Ravi S. Sandhu · 2001
In a two-party RSA signature scheme, a client and server, each holding a share of an RSA decryption exponent d, collaborate to compute an RSA signature under the corresponding public key N, e known to both. We show how Boyd's framework gives rise to a family of practical schemes that although quite similar have surprisingly different security properties. To capture this we suggest two notions of security for two-party signature schemes and provide proofs of security for all the schemes in our family based on appropriate assumptions about RSA and the