ElGamal signature scheme;
public key cryptography;
cryptanalysis;
D O I:
10.1080/09720529.2014.927648
中图分类号:
O29 [应用数学];
学科分类号:
070104 ;
摘要:
Consider the classical ElGamal digital signature scheme based on the modular relation alpha(m) = y(r) r(s)[p]. In this work, we prove that if we can compute a natural integer i such that alpha(i) mod p is smooth and divides p - 1, then it is possible to sign any given document without knowing the secret key. Therefore we extend and reinforce Bleichenbacher's attack presented at Eurocrypt'96.