An elliptic curve backdoor algorithm for RSASSA

  • Authors:
  • Adam Young;Moti Yung

  • Affiliations:
  • Cryptovirology Labs;RSA Labs and Columbia University

  • Venue:
  • IH'06 Proceedings of the 8th international conference on Information hiding
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

We present the first (1,2)-SETUP algorithm for the RSA digital signature scheme with appendix. A SETUP algorithm C′ is an algorithmic modification of algorithm C that (1) contains an asymmetric backdoor that can only be used by the designer, even if the backdoor algorithm is fully public, and (2) ensures that the public outputs of C and C′ are computationally indistinguishable under black-box queries. The SETUP is presented in RSASSA-PSS and it transmits the RSA private key within two w.l.o.g consecutive digital signatures. This problem has been solved for DSA and other discrete-log based digital signature algorithms, but not RSA. We therefore solve a long-standing problem in kleptography.