On the Security of the PKCS#1 v1.5 Signature Scheme

On the Security of the PKCS#1 v1.5 Signature Scheme
复制标题

论PKCS的安全性

DOI:
10.1145/3243734.3243798
复制
发表时间:
2018
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Alexander May
Alexander May
中科院分区:
--
文献类型:
--
作者:
Tibor Jager;Saqib A. Kakvi;Alexander May

文献摘要

参考文献

被引文献

相似文献

RSA PKCS#1 v1.5签名算法是实践中使用最广泛的数字签名方案。它的两个主要优点是非常简单,这使得它非常容易实现,并且签名的验证比DSA或ECDSA快得多。尽管RSA PKCS#1 v1.5签名具有巨大的实际重要性,但事实证明,基于合理的加密硬度假设为其安全性提供正式证据是非常困难的。因此,最新版本的PKCS#1(RFC 8017)甚至建议用更复杂和效率更低的方案RSA-PSS来替代,因为它是可证明安全的,因此被认为更健壮。主要障碍是RSA PKCS#1 v1.5签名使用确定性填充方案,这使得标准证明技术不适用。我们介绍了一种新的技术,使第一个安全证明的RSA-PKCS#1 v1.5签名。在标准RSA假设下,我们证明了自适应选择消息攻击(EUF-CMA)的完全存在不可伪造性。在Phi-Hiding假设下给出了一个严格的证明。这些证明都是在随机预言模型中进行的,并且参数与标准使用略有偏差,因为我们需要更大的哈希函数输出长度。然而,我们还展示了如何在实践中实例化RSA-PKCS#1 v1.5签名,以便我们的安全证明适用。为了更全面地了解RSA PKCS#1 v1.5签名的精确安全性,我们还在标准模型中给出了安全性证明,但针对较弱的攻击者模型(仅密钥攻击)并基于已知的复杂性假设。我们工作的主要结论是,从可证明的安全性角度来看,如果适当选择散列函数的输出长度,RSA PKCS#1 v1.5可以安全地使用。
The RSA PKCS#1 v1.5 signature algorithm is the most widely used digital signature scheme in practice. Its two main strengths are its extreme simplicity, which makes it very easy to implement, and that verification of signatures is significantly faster than for DSA or ECDSA. Despite the huge practical importance of RSA PKCS#1 v1.5 signatures, providing formal evidence for their security based on plausible cryptographic hardness assumptions has turned out to be very difficult. Therefore the most recent version of PKCS#1 (RFC 8017) even recommends a replacement the more complex and less efficient scheme RSA-PSS, as it is provably secure and therefore considered more robust. The main obstacle is that RSA PKCS#1 v1.5 signatures use a deterministic padding scheme, which makes standard proof techniques not applicable. We introduce a new technique that enables the first security proof for RSA-PKCS#1 v1.5 signatures. We prove full existential unforgeability against adaptive chosen-message attacks (EUF-CMA) under the standard RSA assumption. Furthermore, we give a tight proof under the Phi-Hiding assumption. These proofs are in the random oracle model and the parameters deviate slightly from the standard use, because we require a larger output length of the hash function. However, we also show how RSA-PKCS#1 v1.5 signatures can be instantiated in practice such that our security proofs apply. In order to draw a more complete picture of the precise security of RSA PKCS#1 v1.5 signatures, we also give security proofs in the standard model, but with respect to weaker attacker models (key-only attacks) and based on known complexity assumptions. The main conclusion of our work is that from a provable security perspective RSA PKCS#1 v1.5 can be safely used, if the output length of the hash function is chosen appropriately.
DOI: 10.1007/978-3-662-49896-5_10
发表时间: 2016-05
期刊: --
影响因子: --
作者:
Christoph Bader;Tibor Jager;Yong Li;Sven Schäge
通讯作者: Christoph Bader;Tibor Jager;Yong Li;Sven Schäge
DOI: 10.1007/s00145-016-9238-4
发表时间: 2010-08
影响因子: 3
作者:
Eike Kiltz;Adam O'Neill;Adam D. Smith
通讯作者: Eike Kiltz;Adam O'Neill;Adam D. Smith