Re: RSA padding questions
- From: "vedaal" <vedaal@xxxxxxxxx>
- Date: 26 Sep 2006 08:09:10 -0700
Joseph Ashwood wrote:
assume a plaintext of 'm1', encrypted using RSA and standard OAEP
padding, to produce a ciphertext 'c'
is it possible to construct a different padding system, so that a
different plaintext 'm2',
encrypted with the same RSA key, but with the new padding,
still produces the same ciphertext 'c' ?
It's always possible to do that, just don't know why you'd really want to,
it would be extremely insecure. You're talking about steganography, the
problem is that with stego there is a basic assumption that they don't know
there is a (second) message, here they know.
Thanks, for answering,
(btw,
sometimes, (here in sci.crypt), i don't know what to make of a ' no
answer ' ...
as i take pains to avoid trolling or flaming,
a ' no answer' sort of feels like:
" it' really too obvious to explain without making you feel stupid,
and you really didn't post anything deserving of an rtfm/stfw
brush-off,
so maybe it's best just not to answer ... "
so, just for the record,
i * appreciate and am thankful for *
any answers that help me learn,
even if accompanied by ' flames of frustration ' ;-) )
ok,
that said,
i don't understand why a second message would be detectable,
if:
(a) a secure, non-OAEP padding is used,
and kept padding method kept secret between the correspondents,
(b) m1 is meaningful (decoy) plaintext
but,
if what you are saying,
is that the only way that this could be done, is to have m1 be
gibberish plaintext,
easily distinguishable from ciphertext,
then i agree,
it wouldn't be an effective stego channel
( but if it ' could ' be done,
then it would approach the Holy Grail of stego,
in providing a zero-distortion carrier channel,
plausibly deniable,
as well as providing the attackers with
false confidence and useful dis-information )
TIA,
vedaal
.
- Follow-Ups:
- Re: RSA padding questions
- From: Joseph Ashwood
- Re: RSA padding questions
- References:
- RSA padding questions
- From: vedaal
- Re: RSA padding questions
- From: Joseph Ashwood
- RSA padding questions
- Prev by Date: sbox hacking [power functions]
- Next by Date: NMR experiment factors numbers with Gauss sums - A threat to RSA ?
- Previous by thread: Re: RSA padding questions
- Next by thread: Re: RSA padding questions
- Index(es):
Relevant Pages
|