## 数学代写|密码学Cryptography Theory代考|What is a digital signature?

Confidentiality

Signature

Data integrity

Certification

Authentication

Non-repudiation

Message authentication

Revocation
Conventional vs digital

A conventional signature is physically attached to a message.

A conventional signature is verified by comparing to other authentic signatures.

A copy of a signed conventional document can usually be distinguished from the original.
Two classes of signature

Digital signature with appendix

Digital signature with message recovery
Definition 33 (Signature scheme).
A signature scheme is a five-tuple $(\mathcal{P}, \mathcal{A}, \mathcal{K}, \mathcal{S}, \mathcal{V})$

$\mathcal{P}$, a finite set of possible messages

$\mathcal{A}$, a finite set of possible signatures

$\mathcal{K}$, a keyspace, the finite set of possible keys.

For each key $k$ there is a signing algorithm $\operatorname{sig}_k: \mathcal{P} \rightarrow \mathcal{A}$ and a corresponding verification algorithm $\operatorname{ver}_k: \mathcal{P} \times \mathcal{A} \rightarrow{t, f}$ such that for all messages $x$ and all signatures $y$ :
$$\operatorname{ver}_k(x, y)= \begin{cases}t & \text { if } y=\operatorname{sig}_k(x) \ f & \text { if } y \neq \operatorname{sig}_k(x)\end{cases}$$

## 数学代写|密码学Cryptography Theory代考|What do we mean by secure?

Attack models

• Key-only attack
• Known message attack
• Chosen message attack
Goals
There are several goals an attacker might have:
• Total break
• Selective forgery
• Existential forgery
Signing and encrypting?
What if I want confidentiality as well?
Given a message $x$ Alice wishes to sign and encrypt for Bob she has two choices:

Compute her signature on $x, y=\operatorname{sig}{\text {Alice }}(x)$ then encrypt both $x$ and $y$ for Bob, $z=$ $e{\text {Bob }}(x, y)$ or

Encrypt $x$ for Bob, $z=e_{\mathrm{Bob}}(x)$ and sign the result, $y=\operatorname{sig}_{\text {Alice }}(z)$
Which one is the right way round?
Why?

## 数学代写|密码学理论代考|什么是数字签名？

$mathcal{P}$，一个有限的可能信息集

$mathcal{A}$ ，一个可能的签名的有限集合

$mathcal{K}$，一个密钥空间，可能的密钥的有限集合。

