Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

The Insecurity of Nyberg-Rueppel and Other DSA-Like Signature Schemes with Partially Known Nonces

Edwin El MahassniContact Information, Phong Q. NguyenContact Information and Igor E. ShparlinskiContact Information

(5)  Department of Computing, Macquarie University, NSW, 2109, Australia
(6)  Département d’Informatique, École Normale Supérieure, 45 rue d’Ulm, 75005 Paris, France
(7)  Department of Computing, Macquarie University, NSW, 2109, Australia
Abstract
It has recently been proved by Nguyen and Shparlinski that the Digital Signature Algorithm (DSA) is insecure when a few consecutive bits of the random nonces k are known for a reasonably small number of DSA signatures. This result confirmed the efficiency of some heuristic lattice attacks designed and numerically verified by Howgrave-Graham and Smart. Here, we extend the attack to the Nyberg-Rueppel variants of DSA. We use a connection with the hidden number problem introduced by Boneh and Venkatesan and new bounds of exponential sums which might be of independent interest.

Keywords  DSA - Closest Vector Problem - Hidden Number Problem - Exponential Sums

Part of this work is an output of the “Turbo-signatures” project, supported by the French Ministry of Research.
Work supported in part by the Australian Research Council.

Contact Information Edwin El Mahassni
Email: eelmaha@ics.mq.edu.au

Contact Information Phong Q. Nguyen
Email: pnguyen@ens.fr
URL: http://www.di.ens.fr/~pnguyen/

Contact Information Igor E. Shparlinski
Email: igor@ics.mq.edu.au
URL: http://www.comp.mq.edu.au/~igor/
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Remote Address: 38.107.191.109 • Server: mpweb16
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)