6.0 KiB
Digital Signatures
- A signature is proof of authenticity of the sender
- Verification is performed by checking the signature against a known signature
- Mostly works for the real world, not very robust
- This does not scale
Electronic Signature
- Create a binary signature and append this to any document
This is incredibly easy to forge, we need a cryptographic solution
- In many cases two parties will share a symmetric key
k
Verification
To verify a message one must have the message and the signature
(x,y)\rightarrow ver_k(x,y)=\begin{cases}\textrm{True; y is valid}\\\textrm{False; y is invalid}\end{cases}
Non-repudiation
Symmetric keys for verification don’t work, because both parties have access to key
k, either party can sign it.Bob needs to be able to prove that Alice and no one else signed the signature
This requires using a private key
Symetric Signatures gives us:
Authenticity: The sender is confirmed as authentic - only Alice or Bob could have generated the signature
Integrity: The signature confirms the message hasn’t been altered - this is better than the real-world signature scheme
Non-Repudiation: We don’t have this - the symmetric key means that either Alice or Bob could have sent the message
Pubic Key Signatures
- By using asymmetric cryptography we have non-repudiation.
RSA Signatures
Notation:
m- messages- signature
Efficiency
Signing: x^d\mod n
Verification: s^e\mod n
- Signing and verification require one use of the square and multiply algorithm
- Efficiency depends on the exponents
- We often keep
esmall65537=2^{16}+1=10000000000001_2
- This prioritises verification speed
Signature Forgeries
- A forgery is the ability to create a valid message / signature pair
(m,s)wheremhasn’t previously been signed by the legitimate signer- For example replay attack using a previous
(m,s)wouldn’t count as a forgery - As we cannot control the message contents
- For example replay attack using a previous
- Various severities of attack exist depending on the control over the message
m
Existential Forgeries
- The attacker is able to create a valid message / signature pair
(m,s) - There are no constraints on
m, it may well be entirely random mdoes not need to be a valid message to be understood by a recipient
An attacker has access to Alice’s public key (n,e)
- They can calculate
s=\textrm{random}m' =s^e\mod n
- It is trival to generate message and signature pairs based on an RSA public key
- Not very useful
Selective Forgeries
- The attacker is able to create a valid message / signature pair
(m,s)where they have selectedmin advanced mmay have some mathematical proprieties, or be all zeros etc- It is a requirement that
mbe fixed prior to the attack
Universal Forgeries
- The attacker can create a valid signature from any message
m - This is the strongest attack, and implies the previous attacks too
- In RSA, this would imply the attack has access to the private key
Malleability
- RSA is also malleable:
RSA(m_1\cdot m_2)=RSA(m_1)\cdot RSA(m_2) - Given two messages
x_1, x_2and corresponding signaturess_1,s_2(m_3,s_3)\equiv(m_1\cdot m_2, s_1\cdot s_2)(\mod m)
- This is more control for an attacker than we would like to have for a signature scheme
- Malleability is a weakness of encryption with textbook RSA too
Padding
- If we enforce rules about valid formatting on
m, random messages produced by attackers are unlikely to pass - Likelihood of a successful forgery is
2^{-y}- Probability of last bit
2^{-1} - Probability of last 2 bits
2^{-2} - etc up to
y
- Probability of last bit
Hash-then-sign
- It is common to hash the message within any padding scheme
sig_{k_{prvA}}(x)\equiv H(x)^d \mod n
- Verification recomputes the hash
ver_{k_{pubA}}(x,s)= s^e \mod n \equiv H(x)'H(x)\stackrel{?}{=}H(x)'
- Existential forgeries are much harder
- You’d need a random message that’s also a valid hash
- Longer messages can be signed, the hash outputs a smaller message digest
PKCS v1.5
Public Key Cryptography Standards
- Modern padding schemes use hashing and padding for security
- Prevents existential forgeries, and attacks on small messages
- This is deterministic, the same message gives the same signature
RSASSA-PSS
RSA Signature Scheme with Appendix
- “with appendix” refers to any scheme that sends
(m,s)separately - PKCS and similar schemes are deterministic
- The probabilistic signature scheme adds a random salt to the process, meaning repeated singatures on the same document produce different results
- Doesn’t effect security that much, some standards have gone back to a probabilistic approach
PSS Encoding
- Hash message
- Concatenate padding, hash and salt to create
M' - Hash
M’into final hashH - Append padding to salt to create data block
DB - Expand
HusingMGF - Calculate
DB \oplus MGF(H)to create maskedDB - Output is maskedDB,
Hand a constant0xbc0xbcis just a constant, no specific meaning other than formatting
- Use RSA to calculate signature and send
(m,s)as normal
PSS Verifying
(if any of these steps fail, return false)
- Use RSA public key to obtain unsigned signature
- Check length and
0xbcconstant - Split signature into maskedDB and
H - Calculate
MGF(H)and thereforeDB - Check
DBpadding00 .. .. 00 1 - Extract salt from
DB - Recreate
M'from padding, message and salt - Calculate
H(M') - Verify
H(M')=H
Nothing is faster than RSA verification, signing is slower
Its quick because of how 65537 is structured







