At Crypto ’85, Desmedt and Odlyzko described a chosen-ciphertext attack against plain RSA encryption. The technique can also
be applied to RSA signatures and enables an existential forgery under a chosen-message attack. The potential of this attack
remained untapped until a twitch in the technique made it effective against two very popular RSA signature standards, namely
iso/iec 9796-1 and
iso/iec 9796-2. Following these attacks,
iso/iec 9796-1 was withdrawn and ISO/IEC 9796-2 amended. In this paper, we explain in detail Desmedt and Odlyzko’s attack as well
as its application to the cryptanalysis of
iso/iec 9796-2.
Keywords RSA - cryptanalsis - signature - forgery - smoothness - Index Calculation - ISO 9796
Communicated by: P. Wild
AMS Classification: 11T71, 14G50, 94A60