International Workshop on Public Key Cryptography

PKC 2011: Public Key Cryptography – PKC 2011 pp 351-368

On the Impossibility of Instantiating PSS in the Standard Model

  • Rishiraj Bhattacharyya
  • Avradip Mandal
Conference paper

DOI: 10.1007/978-3-642-19379-8_22

Volume 6571 of the book series Lecture Notes in Computer Science (LNCS)

Abstract

In this paper we consider the problem of securely instantiating Probabilistic Signature Scheme (PSS) in the standard model. PSS, proposed by Bellare and Rogaway [3] is a widely deployed randomized signature scheme, provably secure (unforgeable under adaptively chosen message attacks) in Random Oracle Model.

Our main result is a black-box impossibility result showing that one can not prove unforgeability of PSS against chosen message attacks using blackbox techniques even assuming existence of ideal trapdoor permutations (a strong abstraction of trapdoor permutations which inherits all security properties of a random permutation, introduced by Kiltz and Pietrzak in Eurocrypt 2009) or the recently proposed lossy trapdoor permutations [20]. Moreover, we show onewayness, the most common security property of a trapdoor permutation does not suffice to prove even the weakest security criteria, namely unforgeability under zero message attack. Our negative results can easily be extended to any randomized signature scheme where one can recover the random string from a valid signature.

Keywords

PSSBlackbox ReductionsRandomized SignatureStandard Model
Download to read the full conference paper text

Copyright information

© International Association for Cryptologic Research 2011

Authors and Affiliations

  • Rishiraj Bhattacharyya
    • 1
  • Avradip Mandal
    • 2
  1. 1.Cryptology Research Group, Applied Statistics UnitIndian Statistical InstituteKolkataIndia
  2. 2.Université du LuxembourgLuxembourg