# 数学代写|密码学代写Cryptography Theory代考|CS499/CS587 Signature with Privacy

## 数学代写|密码学Cryptography Theory代考|Signature with Privacy

In the RSA DSS, Alice sends the message, signature pair $(M, S)$ with $M$ in plaintext. Thus anyone intercepting the transmission can read Alice’s message. If Alice wants to sign an encrypted message, she should use a “signature with privacy scheme.”
Definition 10.3.1 (RSA Signature with Privacy)
Step 1. Alice establishes a public key and private key pair $\left(s_A, n_A\right), t_A$. Bob establishes a public key and private key pair $\left(s_B, n_B\right), t_B$.
Step 2. Alice signs the message $M$ as
$$S=d\left(M, t_A\right)=\left(M^{t_A} \bmod n_A\right) .$$
Step 3. Alice then encrypts the message $M$ using Bob’s public key:
$$C_1=e\left(M,\left(s_B, n_B\right)\right)=\left(M^{s_B} \bmod n_B\right) .$$
She also encrypts the signature $S$ using Bob’s public key:
$$C_2=e\left(S,\left(s_B, n_B\right)\right)=\left(S^{s_B} \bmod n_B\right) .$$
She then sends the pair $\left(C_1, C_2\right)$ to Bob.
Step 4. Bob uses his private key $t_B$ to recover
$$M=d\left(C_1, t_B\right)=\left(C_1^{t_B} \bmod n_B\right) .$$

He also recovers
$$S=d\left(C_2, t_B\right)=\left(C_2^{t_B} \bmod n_B\right)$$
Step 5. Finally, using Alice’s public key $\left(s_A, n_A\right)$ he authenticates the message by verifying that
$$e\left(S,\left(s_A, n_A\right)\right)=e\left(d\left(M, t_A\right),\left(s_A, n_A\right)\right)=M$$

## 数学代写|密码学Cryptography Theory代考|Security of Digital Signature Schemes

Suppose Alice and Bob are using a digital signature scheme for message authentication. Malice can attack (or break) the digital signature scheme by producing forgeries. Specifically, a forgery is a message, signature pair $(M, S)$ for which $S$ is Alice’s signature of the message $M$.

Essentially, there are two types of forgeries. An existential forgery is a forgery of the form $(M, S)$ for some $M \in \mathcal{M}$. A selective forgery is a forgery of the form $(M, S)$ in which $M$ is chosen by Malice.

Malice will produce forgeries by engaging in several types of attacks. A direct attack is an attack in which Malice only knows Alice’s public key. A knownsignature attack is an attack in which Malice knows Alice’s public key together with a set of message, signature pairs
$$\left(M_1, S_1\right),\left(M_2, S_2\right), \ldots,\left(M_r, S_r\right)$$
signed by Alice. A chosen-message attack is an attack in which Malice knows Alice’s public key and has (somehow) convinced her to sign a set of messages $M_1, M_2, \ldots, M_r$ that Malice has chosen.

Signature with Privacy

Definition 10.3.1 (RSA Signature with Privacy)

$$S=d\left(M, t_A\right)=\left(M^{t_A} \bmod n_A\right) .$$

$$C_1=e\left(M,\left(s_B, n_B\right)\right)=\left(M^{s B} \bmod n_B\right) .$$

$$C_2=e\left(S,\left(s_B, n_B\right)\right)=\left(S^{s_B} \bmod n_B\right) .$$

$$M=d\left(C_1, t_B\right)=\left(C_1^{t_B} \bmod n_B\right) .$$

$$S=d\left(C_2, t_B\right)=\left(C_2^{t_B} \bmod n_B\right)$$

$$e\left(S,\left(s_A, n_A\right)\right)=e\left(d\left(M, t_A\right),\left(s_A, n_A\right)\right)=M$$

Security of Digital Signature Schemes

$$\left(M_1, S_1\right),\left(M_2, S_2\right), \ldots,\left(M_r, S_r\right)$$

