A digital signature scheme secure against adaptive chosenmessage attacks
A digital signature scheme secure against adaptive chosenmessage attacks,10.1137/0217017,Siam Journal on Computing,Shafi Goldwasser,Silvio Micali,Ron
A digital signature scheme secure against adaptive chosenmessage attacks
Citations: 1340
Shafi Goldwasser
Silvio Micali
Ronald L. Rivest
We present a
digital signature scheme
based on the computational diculty of integer factorization. The scheme possesses the novel property of being robust against an adaptive chosenmessage attack: an adversary who receives signatures for messages of his choice (where each message may be chosen in a way that depends on the signatures of previously chosen messages) can not later forge the signature of even a single additional message. This may be somewhat surprising, since the properties of...
Journal:
Siam Journal on Computing  SIAMCOMP
, vol. 17, no. 2, pp. 281308, 1988
DOI:
10.1137/0217017
Citation Context
(886)
...Publickey signatures [12,
17
,25] are relatively expensive to generate...
...For publickey signature schemes, the property corresponding to Unforgeability is Chosen Message Attack (CMA) security [
17
]...
...Perfect Transferability instead of Transferability is effectively a publickey signature scheme secure under CMA [
17
]...
Tom Roeder
,
et al.
MultiVerifier Signatures
...In the classical definition of existential unforgeability (EUF) [
GMR88
], a new signature on an already signed message is not considered a valid forgery—as opposed to strong unforgeability (SUF)...
Olivier Blazy
,
et al.
Signatures on Randomizable Ciphertexts
...Moreover, we need a stronger security guarantee than HW signatures gave us (i.e., existential unforgeability under adaptive chosen message attack [
20
].) We need that: it is not only the case that an adversary cannot produce a pair (m, σ) for a new m; now the adversary cannot even produce the pair (g m ,σ )f or an ew...
Matthew Greenand
,
et al.
Practical Adaptive Oblivious Transfer from Simple Assumptions
...FVDS is secure { existentially unforgeable against adaptive chosen message attacks [
13
] { under the assumption that factorization of an RSA modulus is harder...
Jothi Rangasamy
,
et al.
An integrated approach to cryptographic mitigation of denialofservic...
...Specifically, a signature scheme is leakageresilient in the boundedleakage model if it is existentially unforgeable against an adaptive chosenmessage attack [
19
] even when adversarially chosen functions of the signing key are leaked in an adaptive fashion...
Elette Boyle
,
et al.
Fully LeakageResilient Signatures
