On the security of RSA padding

52Citations
Citations of this article
48Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

This paper presents a new signature forgery strategy. The attack is a sophisticated variant of Desmedt-Odlyzko's method [11] where the attacker obtains the signatures of m1;…; mT−1 and exhibits the signature of an mT which was never submitted to the signer; we assume that all messages are padded by a redundancy function μ before being signed. Before interacting with the signer, the attacker selects T smooth1 μ(mi)-values and expresses μ(mT) as amultiplicative combination of the padded strings μ(m1),…,μ(mT−1). The signature of MT is then forged using the homomorphic property of RSA. A padding format that differs from iso 9796-1 by one single bit was broken experimentally (we emphasize that we could not extend our attack to ISO 9796-1); for iso 9796-2 the attack is more demanding but still much more efficient than collision-search or factoring. For din ni-17.4, pkcs #1 v2.0 and ssl-3.02, the attack is only theoretical since it only applies to speciffic moduli and happens to be less efficient than factoring; therefore, the attack does not endanger any of these standards.

Cite

CITATION STYLE

APA

Coron, J. S., Naccache, D., & Stern, J. P. (1999). On the security of RSA padding. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 1666, pp. 1–18). Springer Verlag. https://doi.org/10.1007/3-540-48405-1_1

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free