Presentation 1995/7/21
Weakness in Message recovery signature schemes based on discrete logarithm problems 1
Atsuko Miyaji,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) Nyberg and Rueppel recently proposed a new digital signature scheme with message recovery feature ([7,8]). Some variants and their applications on it are discussed ([3]). One of their effective applications is the authenticated key exchange. We show these signatures are vulnerable to a known-message attack. This attack becomes serious especially in the authenticated key exchange if a generic chosen-message attack (nonadaptive) is assumed : a forger can exchange an authenticated key successfully. Furthermore we analyze how to defend the attack. We also investigate how to apply the attack to the message recovery signature on an elliptic curve ([4, 5]).
Keyword(in Japanese) (See Japanese page)
Keyword(in English) discrete logarithm problems / message-recovery signature / attack
Paper #
Date of Issue

Conference Information
Committee ISEC
Conference Date 1995/7/21(1days)
Place (in Japanese) (See Japanese page)
Place (in English)
Topics (in Japanese) (See Japanese page)
Topics (in English)
Vice Chair

Paper Information
Registration To Information Security (ISEC)
Language ENG
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) Weakness in Message recovery signature schemes based on discrete logarithm problems 1
Sub Title (in English)
Keyword(1) discrete logarithm problems
Keyword(2) message-recovery signature
Keyword(3) attack
1st Author's Name Atsuko Miyaji
1st Author's Affiliation Information and Communications Technology Laboratory Matsushita Electric Industrial Co., LTD.()
Date 1995/7/21
Paper #
Volume (vol) vol.95
Number (no) 172
Page pp.pp.-
#Pages 11
Date of Issue