Digital Signatures

1. Scope of the Lecture

This lecture introduces digital signatures as the public-key counterpart of message authentication codes. It begins with textbook RSA signatures, explains why the obvious construction is insecure, formalizes existential unforgeability under chosen-message attacks, gives certificates as an important application, and finally proves the security of RSA Full-Domain Hash in the random-oracle model under the RSA assumption.

The course-topic overview places digital signatures in the authenticity side of public-key cryptography:

Security goal Symmetric-key cryptography Public-key cryptography
Privacy Symmetric-key encryption Public-key encryption
Authenticity Message authentication codes Digital signatures

More advanced cryptographic tasks build on these basic primitives.

2. From Symmetric Authentication to Digital Signatures

2.1. Recap: message authentication codes

A message authentication code authenticates a message \(m\) by attaching a tag

\[ t = \mathsf{Mac}(K,m). \]

Every member of the closed group shares the same secret key \(K\). This gives message integrity inside the group, but authentication and verification are symmetric: anyone who can verify a tag can also generate a valid tag.

This is unsuitable when the ability to authenticate must be separated from the ability to verify. For example, suppose Alice and her bank share a MAC key and the message is

\[ m=(100\text{ euros},\mathsf{Bob},\mathsf{Alice}). \]

The bank can verify Alice’s MAC, but because it knows the same key, it can also create a valid MAC on a transaction and claim that Alice authorized it. A publicly verifiable signature should instead let Alice alone sign while letting the bank, and potentially everybody else, verify.

2.2. The asymmetric separation

A digital-signature scheme separates the two capabilities:

  • a secret signing key \(sk\) is used to create signatures;
  • a public verification key \(vk\) is used to check signatures.

Consequently, learning how to verify does not give a verifier the power to sign. Digital signatures were introduced by Rivest, Shamir, and Adleman in 1978 and were the first major non-encryption use of public-key cryptography.

3. Textbook RSA Signatures

3.1. Construction

The motivating idea is to run textbook RSA in the opposite algebraic direction. RSA key generation chooses a modulus \(N=PQ\), a public exponent \(e\), and a secret exponent \(d\) satisfying

\[ ed \equiv 1 \pmod{\varphi(N)}. \]

The keys are

\[ sk=(N,d), \qquad vk=(N,e). \]

To sign a representative \(m\in\mathbb Z_N\), compute

\[ \sigma \leftarrow m^d \bmod N. \]

To verify, check whether

\[ \sigma^e \equiv m \pmod N. \]

Correctness follows from the RSA relation between \(e\) and \(d\). At first glance, security also seems plausible: producing \(\sigma\) appears to require inverting the public RSA map

\[ x\longmapsto x^e\bmod N. \]

Nevertheless, one-wayness alone does not make this signature scheme secure.

3.2. Multiplicative malleability

Textbook RSA is multiplicatively malleable. Given signatures

\[ \sigma_1=m_1^d\bmod N, \qquad \sigma_2=m_2^d\bmod N, \]

an attacker can multiply them:

\[ \sigma=\sigma_1\sigma_2\bmod N. \]

The product is a valid signature on \(m_1m_2\bmod N\), because

\begin{equation*} \begin{aligned} \sigma^e &\equiv (\sigma_1\sigma_2)^e \pmod N\\ &\equiv \sigma_1^e\sigma_2^e \pmod N\\ &\equiv m_1m_2 \pmod N. \end{aligned} \end{equation*}

Thus, after requesting signatures on \(m_1\) and \(m_2\), the attacker can normally output a valid signature on the new message \(m_1m_2\bmod N\).

3.3. Forging a signature on a random message

An attacker does not even need existing signatures to create a valid message-signature pair. It may choose an arbitrary \(\sigma\in\mathbb Z_N\) and define

\[ m=\sigma^e\bmod N. \]

Then \((m,\sigma)\) passes verification by construction. The attacker does not control which meaningful message it obtains, but existential unforgeability asks that it be unable to produce a valid signature on any fresh message. Hence this already constitutes a forgery.

3.4. Signatures are not simply reversed encryption

The RSA equations make signing look like decryption and verification look like encryption, but this is only an algebraic resemblance. Encryption and signatures have different syntax, correctness conditions, adversarial capabilities, and security goals. Reversing an arbitrary secure public-key encryption scheme does not in general produce a secure signature scheme, and textbook RSA itself demonstrates why the analogy is insufficient.

4. Formal Definition of a Digital-Signature Scheme

A digital-signature scheme consists of three probabilistic-polynomial-time algorithms

\[ (\mathsf{Gen},\mathsf{Sign},\mathsf{Verify}). \]

4.1. Key generation

\[ (vk,sk)\leftarrow\mathsf{Gen}(1^\lambda). \]

The randomized algorithm receives the unary security parameter and returns a public verification key \(vk\) and a secret signing key \(sk\).

4.2. Signing

\[ \sigma\leftarrow\mathsf{Sign}(sk,m). \]

Signing receives the secret key and a message and outputs a signature. The general syntax permits signing to be randomized, although a particular scheme, such as the RSA construction later in the lecture, may be deterministic.

4.3. Verification

\[ b\leftarrow\mathsf{Verify}(vk,m,\sigma), \qquad b\in\{0,1\}. \]

Verification is deterministic. Output \(1\) means that the signature is accepted; output \(0\) means that it is rejected.

4.4. Correctness

For every security parameter \(\lambda\in\mathbb N\) and every valid message \(m\), an honestly generated signature must always verify:

\[ \Pr\!\left[ \mathsf{Verify}(vk,m,\mathsf{Sign}(sk,m))=1 \right]=1, \]

where

\[ (vk,sk)\leftarrow\mathsf{Gen}(1^\lambda). \]

The probability is over the randomness of key generation and, when applicable, signing.

5. Existential Unforgeability under Chosen-Message Attacks

5.1. The EUF-CMA experiment

The security notion for signatures closely parallels the corresponding notion for MACs. For an adversary \(\mathcal A\), the experiment

\[ \mathsf{EUF\mbox{-}CMA}_{\mathcal A}(\lambda) \]

proceeds as follows.

  1. The challenger generates

    \[ (vk,sk)\leftarrow\mathsf{Gen}(1^\lambda) \]

    and gives \(vk\) to \(\mathcal A\).

  2. The adversary may adaptively submit polynomially many messages \(m_1,\ldots,m_q\) to a signing oracle. For every query \(m_i\), it receives

    \[ \sigma_i\leftarrow\mathsf{Sign}(sk,m_i). \]

  3. Eventually, the adversary outputs a purported forgery

    \[ (m^*,\sigma^*). \]

  4. The experiment outputs \(1\) precisely when

    \[ \mathsf{Verify}(vk,m^*,\sigma^*)=1 \]

    and

    \[ m^*\notin\{m_1,\ldots,m_q\}. \]

Otherwise, it outputs \(0\).

The messages may be chosen adaptively: a later query can depend on the public key and on signatures returned for earlier queries. The forged message must be fresh. Merely producing a different signature for an already signed message does not win this particular experiment; that stronger requirement belongs to strong unforgeability.

5.2. Security definition

A signature scheme is EUF-CMA secure if, for every PPT adversary \(\mathcal A\), there exists a negligible function \(\nu\) such that, for every \(\lambda\),

\[ \Pr\!\left[ \mathsf{EUF\mbox{-}CMA}_{\mathcal A}(\lambda)=1 \right] <\nu(\lambda). \]

Thus, even after obtaining signatures on messages of its own choice, an efficient attacker has only negligible probability of signing one new message.

6. Application: Certificates

Digital signatures make it possible to authenticate a public key received from a web service. A certification authority (CA) has its own verification key \(vk_{\mathsf{CA}}\) and signing key. The CA signs a statement that binds a service identity, such as a domain name, to the service’s public key \(pk\). A client that trusts \(vk_{\mathsf{CA}}\) can verify this certificate and thereby gain confidence that \(pk\) belongs to the intended service.

This shifts the question to how trust in the CA is established. It must be bootstrapped: trusted root-CA verification keys are distributed in advance, for example in an operating system or browser. Root CAs may certify intermediate CAs, and intermediate CAs may certify end entities, forming a certificate chain.

The slides identify X.509 as the standard used for such certificates and show a public-key infrastructure in which a root CA supports different certificate uses, including e-mail certificates, TLS/SSL certificates, and software/code certificates.

7. RSA Hash-and-Sign / Full-Domain Hash RSA

7.1. Motivation and construction

The multiplicative attack works because textbook RSA signs an algebraically structured message representative directly. RSA Hash-and-Sign first maps an arbitrary bit string through a hash function and signs the resulting value.

Let \(\mathsf{RSAGen}\) generate RSA instances, and let

\[ H:\{0,1\}^*\longrightarrow\mathbb Z_N \]

be a hash function whose range covers the full RSA domain. This construction is therefore also called Full-Domain Hash RSA (FDH-RSA).

The algorithms are as follows.

7.1.1. Key generation

Compute

\[ (N,e,d)\leftarrow\mathsf{RSAGen}(1^\lambda) \]

and output

\[ vk=(N,e), \qquad sk=(N,d). \]

7.1.2. Signing

For \(sk=(N,d)\), compute

\[ \sigma\leftarrow H(m)^d\bmod N. \]

7.1.3. Verification

For \(vk=(N,e)\), accept exactly when

\[ \sigma^e\equiv H(m)\pmod N. \]

Correctness follows from the RSA relation:

\[ \left(H(m)^d\right)^e \equiv H(m)\pmod N. \]

Hashing prevents an attacker from freely selecting message representatives with the multiplicative relations needed by the textbook attack. The formal theorem requires more than collision resistance: the proof models \(H\) as a random oracle.

8. The RSA Assumption

The RSA experiment \(\mathsf{Exp\mbox{-}RSA}_{\mathcal R}(\lambda)\) for an adversary \(\mathcal R\) is defined as follows.

  1. Generate an RSA instance

    \[ (N,e,d)\leftarrow\mathsf{RSAGen}(1^\lambda). \]

    Concretely, choose random \(\lambda\)-bit primes \(P,Q\), let

    \[ N=PQ, \]

    choose \(e\) so that

    \[ \gcd(e,\varphi(N))=1, \]

    and compute \(d\) satisfying

    \[ ed\equiv1\pmod{\varphi(N)}. \]

  2. Choose a uniform \(r\leftarrow_\$\mathbb Z_N\) and compute

    \[ c\leftarrow r^e\bmod N. \]

  3. Give \((N,e,c)\), but not \(d\) or \(r\), to \(\mathcal R\). It returns a candidate \(r'\):

    \[ r'\leftarrow\mathcal R(N,e,c). \]

  4. Output \(1\) if

    \[ (r')^e\equiv c\pmod N, \]

    and output \(0\) otherwise.

The RSA assumption states that every PPT adversary succeeds only with negligible probability:

\[ \Pr\!\left[ \mathsf{Exp\mbox{-}RSA}_{\mathcal R}(\lambda)=1 \right] \leq\mathsf{negl}(\lambda). \]

In words, given a random RSA image \(c=r^e\bmod N\), it is computationally hard to find any \(e\)-th root of \(c\) without the secret key.

9. EUF-CMA Security of Full-Domain Hash RSA

9.1. Theorem

Assume that the RSA assumption holds and that \(H\) is modeled as a random oracle. Then RSA Hash-and-Sign

\[ (\mathsf{Gen},\mathsf{Sign},\mathsf{Verify}) \]

is EUF-CMA secure.

9.2. Proof strategy

Suppose, toward a contradiction, that an efficient adversary \(\mathcal A\) wins the EUF-CMA experiment with non-negligible probability. Construct an RSA adversary \(\mathcal R\) that receives a challenge

\[ (N,e,c), \qquad c=r^e\bmod N, \]

and must find an \(e\)-th root of \(c\).

The reduction \(\mathcal R\) runs \(\mathcal A\) internally, gives it

\[ vk=(N,e), \]

and simulates both the random oracle and the signing oracle. It does not know the signing exponent \(d\). Its goal is to program one hash value to be the RSA challenge and hope that \(\mathcal A\)’s final forgery is for that message.

9.3. Simulating ordinary random-oracle queries

The reduction keeps a table \(L\). For an ordinary new query \(m_i\), it samples

\[ \sigma_i\leftarrow_\$\mathbb Z_N \]

and defines

\[ h_i=\sigma_i^e\bmod N. \]

It stores

\[ (m_i,h_i,\sigma_i) \]

in \(L\) and answers \(H(m_i)=h_i\). A repeated query receives the previously stored answer, so the simulated oracle remains consistent.

This is distributed exactly like a random-oracle answer: because \(e\) is invertible modulo \(\varphi(N)\), RSA exponentiation is a permutation of the RSA domain. Therefore a uniform \(\sigma_i\) produces a uniform \(h_i\).

The benefit of this representation is that \(\mathcal R\) already knows a valid signature on \(m_i\): it is \(\sigma_i\), since

\[ \sigma_i^e\equiv h_i=H(m_i)\pmod N. \]

9.4. Embedding the RSA challenge

Let \(q_H\) be a polynomial upper bound on the number of distinct random-oracle queries. The reduction chooses a uniform index

\[ j\leftarrow_\$\{1,\ldots,q_H\}. \]

For the \(j\)-th relevant new hash query \(m_j\), it programs

\[ H(m_j)=c \]

instead of generating \(\sigma_j^e\). This answer is still uniform because the RSA challenge \(c=r^e\bmod N\) is itself uniform over the RSA domain. However, the reduction does not know the corresponding root \(r\); finding that root is its RSA task.

Thus the special entry conceptually has the form

\[ (m_j,c,\bot), \]

where \(\bot\) indicates that no signature is known.

9.5. Simulating signing queries

When \(\mathcal A\) requests a signature on \(m_i\), the reduction first ensures that \(H(m_i)\) has a consistent table entry. If it is an ordinary entry, it returns the stored \(\sigma_i\). This is a perfectly valid signature even though \(\mathcal R\) does not know \(d\).

If the signing query is for the special message \(m_j\), the reduction must abort, because answering it would require an \(e\)-th root of \(c\). Notice that if \(m_j\) eventually becomes the fresh forged message, EUF-CMA freshness guarantees that the adversary did not previously request its signature.

9.6. Extracting an RSA inverse from the forgery

Suppose the adversary outputs a valid fresh forgery

\[ (m^*,\sigma^*). \]

If \(m^*\neq m_j\), the reduction aborts. If \(m^*=m_j\), validity gives

\begin{equation*} \begin{aligned} (\sigma^*)^e &\equiv H(m^*) \pmod N\\ &= H(m_j)\\ &= c. \end{aligned} \end{equation*}

Therefore \(\sigma^*\) is an \(e\)-th root of the RSA challenge, and \(\mathcal R\) outputs

\[ r'=\sigma^*. \]

9.7. Success probability and reduction loss

Conditioned on a successful forgery whose message was queried to the random oracle, the uniformly chosen index \(j\) identifies the forged message with probability \(1/q_H\). If

\[ \varepsilon(\lambda) =\Pr[\mathcal A\text{ wins the EUF-CMA experiment}], \]

then, ignoring only the negligible possibility of correctly forging without first learning \(H(m^*)\),

\[ \Pr[\mathcal R\text{ inverts RSA}] \geq \frac{\varepsilon(\lambda)}{q_H}. \]

More explicitly, because a never-queried random-oracle value is independent of the adversary, its chance of satisfying \((\sigma^*)^e=H(m^*)\) without querying \(H(m^*)\) is at most the reciprocal of the RSA-domain size, which is negligible. Including this term gives a bound of the form

\[ \Pr[\mathcal R\text{ inverts RSA}] \geq \frac{\varepsilon(\lambda)-\mathsf{negl}(\lambda)}{q_H}. \]

Under the RSA assumption, the left-hand side is negligible. Since \(q_H\) is polynomially bounded, rearranging yields

\[ \varepsilon(\lambda) \leq q_H\cdot\mathsf{negl}(\lambda)+\mathsf{negl}(\lambda) =\mathsf{negl}(\lambda). \]

This contradicts the assumption that \(\mathcal A\) forges with non-negligible probability and proves the theorem.

10. Final Summary

  1. Digital signatures are the asymmetric counterpart of message authentication codes: a secret key signs, while a public key verifies.
  2. Textbook RSA signatures are insecure. RSA’s multiplicative structure lets signatures be combined, and an attacker can create a valid random message-signature pair by selecting the signature first.
  3. The appropriate basic security notion is EUF-CMA security. Even after adaptively obtaining signatures on chosen messages, an efficient attacker must not be able to sign any fresh message.
  4. Certificates use signatures to bind identities to public keys. Trust is bootstrapped from pre-installed CA verification keys, and X.509 standardizes the relevant certificate infrastructure.
  5. RSA Hash-and-Sign hashes an arbitrary message into the full RSA domain and signs the hash value:

    \[ \sigma=H(m)^d\bmod N. \]

  6. In the random-oracle model, a forgery against Full-Domain Hash RSA can be converted into an inverter for the RSA function. The reduction programs one randomly selected hash response with the RSA challenge and loses a factor of at most \(q_H\) in success probability.

Author: Lowtroo

Created on: 2026-08-03 Mon 18:40

Powered by Emacs 29.3 (Org mode 9.6.15)