Abstract
This paper presents a new signature forgery strategy. The attack is a sophisticated variant of Desmedt-Odlyzko's method [11] where the attacker obtains the signatures of m1;…; mT−1 and exhibits the signature of an mT which was never submitted to the signer; we assume that all messages are padded by a redundancy function μ before being signed. Before interacting with the signer, the attacker selects T smooth1 μ(mi)-values and expresses μ(mT) as amultiplicative combination of the padded strings μ(m1),…,μ(mT−1). The signature of MT is then forged using the homomorphic property of RSA. A padding format that differs from iso 9796-1 by one single bit was broken experimentally (we emphasize that we could not extend our attack to ISO 9796-1); for iso 9796-2 the attack is more demanding but still much more efficient than collision-search or factoring. For din ni-17.4, pkcs #1 v2.0 and ssl-3.02, the attack is only theoretical since it only applies to speciffic moduli and happens to be less efficient than factoring; therefore, the attack does not endanger any of these standards.
Cite
CITATION STYLE
Coron, J. S., Naccache, D., & Stern, J. P. (1999). On the security of RSA padding. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 1666, pp. 1–18). Springer Verlag. https://doi.org/10.1007/3-540-48405-1_1
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.