Security Analysis of the Gennaro-Halevi-Rabin Signature Scheme
We exhibit an attack against a signature scheme recently proposed by Gennaro, Halevi and Rabin . The scheme’s security is based on two assumptions namely the strong RSA assumption and the existence of a division-intractable hash-function. For the latter, the authors conjectured a security level exponential in the hash-function’s digest size whereas our attack is sub-exponential with respect to the digest size. Moreover, since the new attack is optimal, the length of the hash function can now be rigorously fixed. In particular, to get a security level equivalent to 1024-bit RSA, one should use a digest size of approximately 1024 bits instead of the 512 bits suggested in .
KeywordsHash Function Signature Scheme Security Level Random Oracle Common Multiple
- 2.N. Barić and B. Pfitzmann, Collision-free accumulators and fail-stop signature scheme without trees, proceedings of Eurocrypt’97, LNCS vol. 1233, Springer-Verlag, 1997, pp. 480–494.Google Scholar
- 3.M. Bellare and P. Rogaway, Random oracles are practical: a paradigm for designing efficient protocols. Proceedings of the First Annual Conference on Computer and Commmunications Security, ACM, 1993.Google Scholar
- 6.J.S. Coron and D. Naccache, Security analysis of the Gennaro-Halevi-Rabin signature scheme, full version of this paper, available at http://www.eleves.ens.fr:8080/home/coron, 2000.
- 7.K. Dickman, On the frequency of numbers containing prime factors of a certain relative magnitude, Arkiv för matematik, astronomi och fysik, vol. 22A, no. 10, pp. 1–14, 1930.Google Scholar
- 8.G. Hardy and E. Wright, An introduction to the theory of numbers, Fifth edition, Oxford, 1979, pp. 354–359, 368–370.Google Scholar
- 9.R. Gennaro, S. Halevi and T. Rabin, Secure hash-and-sign signatures without the random oracle, proceedings of Eurocrypt’99, LNCS vol. 1592, Springer-Verlag, 1999, pp. 123–139.Google Scholar
- 12.M.I.R.A.C.L. library, Shamus Software Ltd., 94 Shangan Road, Ballymun, Dublin, Ireland.Google Scholar