On the Impossibility of Proving Security of Strong-RSA Signatures via the RSA Assumption

On the Impossibility of Proving Security of Strong-RSA Signatures via the RSA Assumption
复制标题

DOI:
10.1007/978-3-319-08344-5_19
复制
发表时间:
2014-07
期刊:
--
影响因子:
--
通讯作者:
Masayuki Fukumitsu;Shingo Hasegawa;Shuji Isobe;Hiroki Shizuya
Masayuki Fukumitsu;Shingo Hasegawa;Shuji Isobe;Hiroki Shizuya
中科院分区:
其他
文献类型:
--
作者:
Masayuki Fukumitsu;Shingo Hasegawa;Shuji Isobe;Hiroki Shizuya

文献摘要

相似文献

我们提出一个问题,标准 RSA 假设是否足以证明基于 RSA 的强签名(简称 SRSA)的安全性。在本文中,我们为这个问题提供了负面的间接证据。也就是说,就保模代数约简而言,在 RSA 假设下,多个基于 SRSA 的签名无法被证明是 sEUF-CMA,甚至是 EUF-KOA。我们的结果是 Catalano、Fiore 和 Warinschi 提出的自适应伪自由群的一个重要应用,可以被视为签名的抽象框架。事实上,我们表明,RSA 群的自适应伪自由性无法通过此类约简从 RSA 假设中得到证明。
We pose a question whether or not the standard RSA assumption is sufficient to prove the security of the strong RSA-based (SRSA-based, for short) signatures. In this paper, we show a negative circumstantial evidence for the question. Namely, several SRSA-based signatures cannot be proven to be sEUF-CMA, or even EUF-KOA, under the RSA assumption as far as a modulus-preserving algebraic reduction is concerned. Our result is obtained as an important application of the adaptive pseudo-free group introduced by Catalano, Fiore and Warinschi that can be regarded as an abstract framework of signatures. We in fact show that the adaptive pseudo-freeness of the RSA groupcannot be proven from the RSA assumption via such reductions.