Re: Determinstic OpenSSL signature

From: Anne & Lynn Wheeler (lynn_at_garlic.com)
Date: 06/02/05

  • Next message: none: "Re: Sociological/Psychological Phenomenon"
    Date: Thu, 02 Jun 2005 15:27:44 -0600
    
    

    bmoeller@acm.org (Bodo Moeller) writes:
    > Other examples: Apart from SSL, you must expect to find this kind of
    > padding in X.509 certificates using RSA signatures (it's not the
    > only scheme in use, but very common). Also RSA signing in PGP uses
    > it.

    one of the somewhat legacies of the 90s has been use of RSA in
    infrastructures that might consider deploying hardware tokens (as a
    integrity mechanism). the tokens from the era typically had very poor
    random number capability ... which is required for key generation
    ... but also required by dsa and ecdsa for every signature generated.

    In the RSA scenario, the infrastructures could implement token key
    injection with the key generation happening on an external device with
    reasonable random number capability.

    there are some peculiarities of dsa/ecdsa signatures (because of the
    random number) vis-a-vis RSA ... if somebody signed the same exact
    data multiple times ... all the signatures would be different (and
    non-deterministic)

    -- 
    Anne & Lynn Wheeler | http://www.garlic.com/~lynn/
    

  • Next message: none: "Re: Sociological/Psychological Phenomenon"

    Relevant Pages

    • Re: Public key encryption
      ... > messages as to break the hash algorithm. ... it amounts to equivalence to the RSA problem. ... anything that can forge PSS signatures can do arbitrary RSA ... > message is small compared to the encryption exponent but still a hash ...
      (sci.crypt)
    • Re: [fw-wiz] Username password VS hardware token plus PIN
      ... > I think the best you can get is SecureID/ACE (used to be AXENT, now RSA?) ... SecurID is unrelated to AXENT's product, ... I converted from the old X9.9/Axent challenge-response tokens after the ... a password-expiration-style PIN change. ...
      (Firewall-Wizards)
    • Re: Time to ask again: Is there anything BETTER than eBay?
      ... Just a footnote on the two-factor authentication tokens mentioned ... Rob said that he already has two RSA SecurID tokens that he uses at ... validate the token-code displayed on a particular SecurID at any given ...
      (uk.people.consumers.ebay)
    • Re: Account hacked using Blizzards Password Reset Utility
      ... (RSA also makes tokens that connect to the USB port, ... and does not use any RSA patents. ... He has to log on before the authentication key changes and ... Should someone manage to snatch a single login key while ...
      (alt.games.warcraft)
    • Re: Public key encryption
      ... The trouble is that RSA is only ... domain hash". ... Actually PSS shows that you can relax this condition very slightly, ... but if you use IEEE 1363 signatures then you get a free license to the ...
      (sci.crypt)

  • Quantcast