93%(14)13 out of 14 people found this document helpful
This preview shows page 2 - 3 out of 3 pages.
Problem 8.3You are to show that it is possible to forge the Plain RSA signature for any particularmessage.Recall that in this scheme the signing algorithm on inputssk= (N, d)andM∈Z*NreturnsMdmodN.Here is the definition that is stronger than thestandard UF-CMA definition in that here the adversary cannot choose the message
in its forgery. LetDS= (K,S,V) be a digital signature scheme with an associatedmessage space MsgSp and letAbe an adversary. Consider the experiment:ExperimentExpeuf-cmaDS(A)(pk,sk)← KM