RSA-Padding Signatures with Attack Studies

A fixed-pattern padding consists in concatenating to the message m a fixed pattern P. An RSA signature for the padding P and message m is obtained by raising the message m and the padding P to the private decryption exponent d. In this paper we prove that the security of RSA fixed-pattern padding is insecure for messages at least two-thirds of the size of n… CONTINUE READING