Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Kahrobaei--Koupparis DSS: universal forgery

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

<div><p>Regardless of the choice of parameters, knowledge of a single signed message, i.e., a pair message/signature, produced by Kahrobaei-Koupparis digital signature scheme, proposed in [D. Kahrobaei and C. Koupparis, 2012], is sufficient to forge a valid signature for any other message. </p></div>

Similar Papers
  • Book Chapter
  • 10.3233/978-1-61499-484-8-2201
Universal Forgery on Shen et al.'s Linkable and Convertible ID-based Ring Signature Scheme
  • Jan 1, 2015
  • Frontiers in artificial intelligence and applications
  • Hwang Shin-Jia

Recently, Shen et al. proposes their ID-based ring signature scheme. Based on the scheme, they also propose their linkable and convertible ID-based ring signature scheme. However, a universal forgery is found for their ID-based ring signature scheme. Therefore, their linkable and convertible ID-based ring signature scheme is also insecure against universal forgeries.

  • Supplementary Content
  • 10.1080/0020716042000272520
Universal forgery on Sekhar's signature scheme with message recovery
  • Dec 1, 2004
  • International Journal of Computer Mathematics
  • F Laguillaumie + 2 more

Owing to the abundance of electronic applications of digital signatures, many additional properties are needed. Recently, Sekhar [Sekhar, M. R. (2004). Signature scheme with message recovery and its application. Int. J. Comput. Math., 81(3), 285–289.] proposed three signature schemes with message recovery designed to protect the identity of the signer. In this setting, only a specific verifier can check the validity of a signature, and he can transmit this conviction to a third party. In this note, we show that this protocol is totally insecure, as it is universally forgeable under a no-message attack. In other words, we show that anyone can forge a valid signature of a user on an arbitrary message. The forged signatures are unconditionally indistinguishable (in an information theoretical sense) from properly formed signatures. E-mail: vergnaud@math.unicaen.fr E-mail: jacques.traore@francetelecom.com

  • Research Article
  • 10.1016/j.ipl.2003.11.014
Universal forgery on a group signature scheme using self-certified public keys
  • Dec 30, 2003
  • Information Processing Letters
  • Guilin Wang

Universal forgery on a group signature scheme using self-certified public keys

  • Book Chapter
  • Cite Count Icon 8
  • 10.1007/978-3-540-72354-7_10
Cryptanalysis of Some Proxy Signature Schemes Without Certificates
  • Jan 1, 2007
  • Wun-She Yap + 2 more

The concept of proxy signature was introduced by Mambo et al. to delegate signing capability in the digital world. In this paper, we show that three existing proxy signature schemes without certificates, namely, the Qian and Cao identity-based proxy signature (IBPS) scheme, the Guo et al. IBPS scheme and the Li et al. certificateless proxy signature (CLPS) scheme are insecure against universal forgery. More precisely, we show that any user who has a valid public-private key pair can act as a cheating proxy signer and forge the proxy signature on behalf of the original signer at will, without obtaining the official delegation from the original signer.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 5
  • 10.3390/info12100433
Algebraic Fault Analysis of SHA-256 Compression Function and Its Application
  • Oct 19, 2021
  • Information
  • Kazuki Nakamura + 2 more

Cryptographic hash functions play an essential role in various aspects of cryptography, such as message authentication codes, pseudorandom number generation, digital signatures, and so on. Thus, the security of their hardware implementations is an important research topic. Hao et al. proposed an algebraic fault analysis (AFA) for the SHA-256 compression function in 2014. They showed that one could recover the whole of an unknown input of the SHA-256 compression function by injecting 65 faults and analyzing the outputs under normal and fault injection conditions. They also presented an almost universal forgery attack on HMAC-SHA-256 using this result. In our work, we conducted computer experiments for various fault-injection conditions in the AFA for the SHA-256 compression function. As a result, we found that one can recover the whole of an unknown input of the SHA-256 compression function by injecting an average of only 18 faults on average. We also conducted an AFA for the SHACAL-2 block cipher and an AFA for the SHA-256 compression function, enabling almost universal forgery of the chopMD-MAC function.

  • Book Chapter
  • Cite Count Icon 83
  • 10.1007/bfb0034859
On the risk of disruption in several multiparty signature schemes
  • Jan 1, 1996
  • Markus Michels + 1 more

Multiparty cryptography is an important topic in contemporary cryptography. In this paper we examine the security of some multiparty signature schemes. In particular, we point out that a multisignature scheme is vulnerable to universal forgery by an insider attacker under reasonable assumptions. This attack can be applied to some generalizations as well. Then we present a universal forgery attack on two threshold group signature schemes with anonymous signers. Furthermore, we show that in two threshold multisignature schemes it can't be guaranteed that a signer can decide with whom he is going to sign a message. All attacks have in common that the protocol is disrupted. Thus they are not undetectable. However, as they can only be detected afterwards and knowledge leaked by protocol disruptions must be useless, such attacks are not acceptable in general and must be avoided. Finally, we suggest some heuristic fixes.

  • Book Chapter
  • Cite Count Icon 31
  • 10.1007/3-540-45067-x_33
Parallel Authentication and Public-Key Encryption
  • Jan 1, 2003
  • Josef Pieprzyk + 1 more

A parallel authentication and public-key encryption is introduced and exemplified on joint encryption and signing which compares favorably with sequential Encrypt-then-Sign (ɛtS) or Sign-then-Encrypt (Stɛ) schemes as far as both efficiency and security are concerned. A security model for signcryption, and thus joint encryption and signing, has been recently defined which considers possible attacks and security goals. Such a scheme is considered secure if the encryption part guarantees indistinguishability and the signature part prevents existential forgeries, for outsider but also insider adversaries. We propose two schemes of parallel signcryption, which are efficient alternative to Commit-then-Sign-and- Encrypt (Ct&G3&S). They are both provably secure in the random oracle model. The first one, called generic parallel encrypt and sign, is secure if the encryption scheme is semantically secure against chosen-ciphertext attacks and the signature scheme prevents existential forgeries against random-message attacks. The second scheme, called optimal parallel encrypt. and sign, applies random oracles similar to the OAEP technique in order to achieve security using encryption and signature components with very weak security requirements — encryption is expected to be one-way under chosen-plaintext attacks while signature needs to be secure against universal forgeries under random-plaintext attack, that is actually the case for both the plain-RSA encryption and signature under the usual RSA assumption. Both proposals are generic in the sense that any suitable encryption and signature schemes (i.e. which simply achieve required security) can be used. Furthermore they allow both parallel encryption and signing, as well as parallel decryption and verification. Properties of parallel encrypt and sign schemes are considered and a new security standard for parallel signcryption is proposed.

  • Research Article
  • 10.46586/uasc.2026.009
SLasH-DSA: Breaking SLH-DSA Using an Extensible End-To-End Rowhammer Framework
  • Feb 3, 2026
  • Proceedings of the Microarchitecture Security Conference
  • Jeremy Boy + 4 more

As quantum computing advances, Post-Quantum Cryptography (PQC) schemes are adopted to replace classical algorithms. Among them is the Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) that was recently standardized by NIST and is favored for its conservative security basis. In this work, we present the first software-only universal forgery attack on SLH-DSA, leveraging Rowhammer-induced bit flips to corrupt the internal state and forge signatures. While prior work targeted embedded systems and required physical access, our attack is software-only, targeting commodity desktop and server hardware, significantly broadening the threat model. We demonstrate full end-to-end attacks against SLH-DSA in OpenSSL 3.5.1, achieving universal forgery for the SHAKE-128f (deterministic), SHA2-128s, and SHAKE-192f (randomized) parameter sets after one hour (deterministic) or eight hours (randomized) of hammering and post-processing ranging from minutes to an hour, and showing theoretical attack complexities for most parameter sets. Our post-processing is informed by a novel complexity analysis that, given a concrete set of faulty signatures, identifies the most promising computational path to pursue. To enable the attack, we introduce Swage, a modular and extensible framework for implementing end-to-end Rowhammer-based fault attacks. Swage abstracts and automates key components of practical Rowhammer attacks. Unlike prior tooling, Swage is untangled from the attacked code, making it reusable and suitable for frictionless analysis of different targets. Our findings highlight that even theoretically sound PQC schemes can fail under real-world conditions, underscoring the need for additional implementation hardening or hardware defenses against Rowhammer.

  • Conference Article
  • 10.1109/icnpcw.2007.4351586
Cryanalysis on a Nonrepudiable Threshold Proxy Signature Scheme with Known Signers
  • Sep 1, 2007
  • Hongguang Xiao + 2 more

In the paper, we analyze the security of C.-L. Hsu et al.'s threshold proxy signature scheme. The scheme suffers from universal forgery and does not hold nonrepudiation. An adversary can forge (t, n) threshold proxy signature on any message m. We propose an improvement to remedy the weakness of C.-L Hsu et al.'s scheme.

  • Conference Article
  • 10.1109/npc.2007.52
Cryanalysis on a Nonrepudiable Threshold Proxy Signature Scheme with Known Signers
  • Sep 1, 2007
  • Hongguang Xiao + 2 more

In the paper, we analyze the security of C.-L. Hsu et al.'s threshold proxy signature scheme. The scheme suffers from universal forgery and does not hold nonrepudiation. An adversary can forge (t, n) threshold proxy signature on any message m. We propose an improvement to remedy the weakness of C.-L Hsu et al.'s scheme.

  • Conference Article
  • 10.1109/icct.2006.341962
Study on a Signature Scheme without Using One-way Hash Functions or Message Redundancy
  • Nov 1, 2006
  • Baozheng Yu + 1 more

Recently, Chang et al. proposed a new digital signature scheme with message recovery without using oneway hash functions or message redundancy schemes. However, Zhang et al. found that Chang et al.'s signature scheme is not secure. He proposed a kind of forgery attack; anyone who has a valid signature generated by the signer, can forge a valid signature, and claimed that only using one-way hash functions or message redundancy schemes can overcome these flaws. In this paper, we first initiate a more simple and efficient universal forgery attack on Chang et al.'s signature scheme compared with Zhang et al.'s attack; anyone can forge a valid signature without using any valid signatures of the signer. Also, we propose an improved signature scheme without using one way hash functions or message redundancy, which can resist the forgery attacks.

  • Conference Article
  • Cite Count Icon 1
  • 10.1109/cis.workshops.2007.81
Security Analysis on a Blind Signature Scheme Based on Elgamal Signature Equation
  • Dec 15, 2007
  • Biao Yu + 1 more

Universal forgery attacks and selected forgery attacks on both weak and strong blind signature schemes based on Elgamal signature equation proposed by Wang et al. are developed. Without using any secret key, anyone can forge a valid signature through selecting some random parameters. The possibility of forging the blind schemes is analyzed and moreover, an improved weak blind signature scheme and an improved strong blind signature scheme are designed. Also, the securities of the improved blind signatures are analyzed.

  • Research Article
  • Cite Count Icon 19
  • 10.1145/505680.505684
On the validity of digital signatures
  • Apr 1, 2000
  • ACM SIGCOMM Computer Communication Review
  • Jianying Zhou + 1 more

An important feature of digital signatures is to serve as non-repudiation evidence. To be eligible as non-repudiation evidence, a digital signature on an electronic document should remain valid until its expiry date which is specified by some non-repudiation policy. As signature keys may be compromised and the validity of signatures may become questionable, additional security mechanisms need to be imposed on digital signatures. This paper examines the mechanisms for maintaining the validity of digital signatures, and provides a guideline on the use of these mechanisms in various context of applications.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 18
  • 10.46586/tches.v2023.i2.80-114
On Protecting SPHINCS+ Against Fault Attacks
  • Mar 6, 2023
  • IACR Transactions on Cryptographic Hardware and Embedded Systems
  • Aymeric Genêt

SPHINCS+ is a hash-based digital signature scheme that was selected by NIST in their post-quantum cryptography standardization process. The establishment of a universal forgery on the seminal scheme SPHINCS was shown to be feasible in practice by injecting a fault when the signing device constructs any non-top subtree. Ever since the attack has been made public, little effort was spent to protect the SPHINCS family against attacks by faults. This paper works in this direction in the context of SPHINCS+ and analyzes the current algorithms that aim to prevent fault-based forgeries.First, the paper adapts the original attack to SPHINCS+ reinforced with randomized signing and extends the applicability of the attack to any combination of faulty and valid signatures. Considering the adaptation, the paper then presents a thorough analysis of the attack. In particular, the analysis shows that, with high probability, the security guarantees of SPHINCS+ significantly drop when a single random bit flip occurs anywhere in the signing procedure and that the resulting faulty signature cannot be detected with the verification procedure. The paper shows both in theory and experimentally that the countermeasures based on caching the intermediate W-OTS+s offer a marginally greater protection against unintentional faults, and that such countermeasures are circumvented with a tolerable number of queries in an active attack. Based on these results, the paper recommends real-world deployments of SPHINCS+ to implement redundancy checks.

  • Book Chapter
  • Cite Count Icon 9
  • 10.1007/978-3-540-30079-3_30
On the Security of the Lee-Hwang Group-Oriented Undeniable Signature Schemes
  • Jan 1, 2004
  • Guilin Wang + 2 more

Undeniable signature is an intriguing concept introduced by Chaum and van Antwerpen at Crypto’89. In 1999, Lee and Hwang presented two group-oriented undeniable signature schemes with a trusted center. Their schemes are natural generalizations of Chaum’s zero knowledge undeniable signature scheme proposed in 1990. However, we find that the Lee-Hwang schemes are insecure. In this paper, we demonstrate five effective attacks on their schemes: four of them are insider universal forgeries, in which one dishonest member (maybe colluding with a verifier) can get a valid signature on any chosen massage, and another attack allows a dishonest member to prevent honest members from generating valid signatures. We also suggest heuristic improvements to overcome some of the problems involved in these attacks.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant