This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -3,7 +3,7 @@
- A signature is proof of authenticity of the sender
- Verification is performed by checking the signature against a known signature
- Mostly works for the real world, not very robust
- This does not scale
- This does not scale
#### Electronic Signature
@@ -33,7 +33,7 @@ $$
>
> This requires using a private key
Symetric Signatures gives us:
Symmetric signatures give us:
**Authenticity**: The sender is confirmed as authentic - only Alice or Bob could have generated the signature
@@ -41,7 +41,7 @@ Symetric Signatures gives us:
**Non-Repudiation**: We don’t have this - the symmetric key means that either Alice or Bob could have sent the message
### Pubic Key Signatures
### Public Key Signatures
- By using asymmetric cryptography we have non-repudiation.
@@ -65,14 +65,14 @@ Verification: $s^e\mod n$
- Signing and verification require one use of the *square and multiply* algorithm
- Efficiency depends on the exponents
- We often keep $e$ small
- $65537=2^{16}+1=10000000000001_2$
- $65537=2^{16}+1=10000000000001_2$
- This prioritises verification speed
##### Signature Forgeries
- A forgery is the ability to create a valid message / signature pair $(m,s)$ where $m$ hasn’t previously been signed by the legitimate signer
- For example replay attack using a previous $(m,s)$ wouldn’t count as a forgery
- As we cannot control the message contents
- For example, a replay attack using a previous $(m,s)$ wouldn’t count as a forgery
- As we cannot control the message contents
- Various severities of attack exist depending on the control over the message $m$
###### Existential Forgeries
@@ -84,49 +84,51 @@ Verification: $s^e\mod n$
An attacker has access to Alice’s public key $(n,e)$
- They can calculate
- $s=\textrm{random}$
- $m' =s^e\mod n$
- It is trival to generate message and signature pairs based on an RSA public key
- Not very useful
- $s=\textrm{random}$
- $m' =s^e\mod n$
- It is trivial to generate message and signature pairs based on an RSA public key
- Not very useful
###### Selective Forgeries
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advanced
- $m$ may have some mathematical proprieties, or be all zeros etc
- The attacker is able to create a valid message / signature pair $(m,s)$ where they have selected $m$ in advance
- $m$ may have some mathematical properties, or be all zeros etc.
- It is a requirement that $m$ be fixed prior to the attack
###### Universal Forgeries
- The attacker can create a valid signature from any message $m$
- This is the strongest attack, and implies the previous attacks too
- In RSA, this would imply the attack has access to the private key
- In RSA, this would imply the attacker has access to the private key
### Malleability
- RSA is also malleable: $RSA(m_1\cdot m_2)=RSA(m_1)\cdot RSA(m_2)$
- Given two messages $x_1, x_2$ and corresponding signatures $s_1,s_2$
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
- $(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)$
- This is more control for an attacker than we would like to have for a signature scheme
- Malleability is a weakness of encryption with textbook RSA too
### Padding
- If we enforce rules about valid formatting on $m$, random messages produced by attackers are unlikely to pass
- ![1649188921.png](img/1649188921.png)
- ![1649188921.png](img/1649188921.png)
- Likelihood of a successful forgery is $2^{-y}$
- Probability of last bit $2^{-1}$
- Probability of last 2 bits $2^{-2}$
- etc up to $y$
- Probability of last bit $2^{-1}$
- Probability of last 2 bits $2^{-2}$
- etc. up to $y$
#### Hash-then-sign
- It is common to hash the message within any padding scheme
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
- $sig_{k_{prvA}}(x)\equiv H(x)^d \mod n$
- Verification recomputes the hash
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
- $H(x)\stackrel{?}{=}H(x)'$
- $ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'$
- $H(x)\stackrel{?}{=}H(x)'$
- Existential forgeries are much harder
- You’d need a random message that’s also a valid hash
- You’d need a random message that’s also a valid hash
- Longer messages can be signed, the hash outputs a smaller message digest
##### PKCS v1.5
@@ -135,7 +137,7 @@ An attacker has access to Alice’s public key $(n,e)$
- Modern padding schemes use hashing and padding for security
- Prevents existential forgeries, and attacks on small messages
- This is deterministic, the same message gives the same signature
- This is deterministic, the same message gives the same signature
![1649192054.png](img/1649192054.png)
@@ -145,8 +147,8 @@ An attacker has access to Alice’s public key $(n,e)$
- “with appendix” refers to any scheme that sends $(m,s)$ separately
- PKCS and similar schemes are deterministic
- The probabilistic signature scheme adds a random salt to the process, meaning repeated singatures on the same document produce different results
- Doesn’t effect security that much, some standards have gone back to a probabilistic approach
- The probabilistic signature scheme adds a random salt to the process, meaning repeated signatures on the same document produce different results
- Doesn’t affect security that much; some standards have gone back to a probabilistic approach
###### PSS Encoding
@@ -157,7 +159,7 @@ An attacker has access to Alice’s public key $(n,e)$
5. Expand $H$ using $MGF$
6. Calculate $DB \oplus MGF(H)$ to create maskedDB
7. Output is maskedDB, $H$ and a constant `0xbc`
- `0xbc` is just a constant, no specific meaning other than formatting
- `0xbc` is just a constant, no specific meaning other than formatting
8. Use RSA to calculate signature and send $(m,s)$ as normal
![1649192548.png](img/1649192548.png)
@@ -180,4 +182,4 @@ An attacker has access to Alice’s public key $(n,e)$
Nothing is faster than RSA verification, signing is slower
Its quick because of how 65537 is structured
It's quick because of how 65537 is structured