Micron Document
____ _ _ _ _
| _ \ ___ | |_ (_) _ __ ___ __| | (_) __ _
| |_) | / _ \ | __| | | | '_ \ / _ \ / _| | | | / _ |
| _ < | __/ | |_ | | | |_) | | __/ | (_| | | | | (_| |
|_| \_\ \___| \__| |_| | .__/ \___| \__,_| |_| \__,_|
|_|


The NomadNet German Wikipedia | Archives | Info
- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b

πŸ” Search

Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―Β―

Probabilistic Signature Scheme
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
Probabilistic Signature Scheme (PSS) oder probabilistisches Signaturverfahren ist ein von Mihir Bellare und Phillip Rogaway entwickeltes kryptographisches Paddingverfahren.cite-ref-br96-1-0[1] Im Zufallsorakelmodell kann mit dem PSS aus einer FalltΓΌrpermutation ein beweisbar sicheres Signaturverfahren konstruiert werden.

Contents

β€’ Verfahren
β€’ Signieren
β€’ Verifizieren

──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

Verfahren

PSS wurde entwickelt, weil es fΓΌr die damals existierenden Signaturverfahren keine Sicherheitsbeweise gab, die die Sicherheit des Signaturverfahrens in eine enge Beziehung zur Schwierigkeit des dem Verfahren zugrundeliegenden Problems setzten. Ein solcher Beweis konnte fΓΌr PSS mit Hilfe von Zufallsorakeln, die ideale kryptologische Hashfunktionen modellieren, angegeben werden.

Signieren

Das Verfahren benutzt eine Hashfunktion H {\displaystyle H} und wird durch drei Werte parametrisiert:

β€’ k {\displaystyle k} , die BitlΓ€nge der Menge auf der die Permutation operiert
β€’ k 0 {\displaystyle k_{0}} , die LΓ€nge der Zufallszahl
β€’ k 1 {\displaystyle k_{1}} , die AusgabelΓ€nge der Hashfunktion H {\displaystyle H}

Zum Signieren wird die Nachricht M {\displaystyle M} zusammen mit einer Zufallszahl r {\displaystyle r} zu einem Wert w = H ( M | r ) {\displaystyle w=H(M|r)} gehasht. Da r {\displaystyle r} zur Verifikation benΓΆtigt wird, wird sie mit g 1 ( w ) {\displaystyle g_{1}(w)} maskiert. Eine weitere Funktion liefert g 2 ( w ) {\displaystyle g_{2}(w)} , die k βˆ’ βˆ’ k 0 βˆ’ βˆ’ k 1 βˆ’ βˆ’ 1 {\displaystyle k-k_{0}-k_{1}-1} fehlenden Bits. Aus dem Bitstring y = 0 | w | r {\displaystyle y=0|w|r} βŠ• {\displaystyle \oplus } g 1 ( w ) | g 2 ( w ) {\displaystyle g_{1}(w)|g_{2}(w)} ist nun mittels der geheimen Umkehrung der Einwegpermutation die Signatur s = P βˆ’ βˆ’ 1 ( y ) {\displaystyle s=P^{-1}(y)} berechnet.

Verifizieren

Um eine Signatur s {\displaystyle s} einer Nachricht M {\displaystyle M} zu verifizieren, wird zuerst y = P ( s ) {\displaystyle y=P(s)} berechnet und in b | w | r β€² | s β€² {\displaystyle b|w|r'|s'} geparst. Dann wird die Zufallszahl r = r β€² βŠ• βŠ• g 1 ( w ) {\displaystyle r=r'\oplus g_{1}(w)} wiedergewonnen und ΓΌberprΓΌft, dass w = H ( M | r ) {\displaystyle w=H(M|r)} , s β€² = g 2 ( w ) {\displaystyle s'=g_{2}(w)} und b = 0 {\displaystyle b=0} ist. Falls diese Bedingungen erfΓΌllt sind, ist die Signatur gΓΌltig, andernfalls nicht.

Varianten RSA-PSS

1996 beschrieben Bellare und Rogaway in ihrem Papier die Kombination von PSS mit RSA als FalltΓΌrpermutation. Im Zufallsorakelmodell ist RSA-PSS existentially unforgeable under chosen-message attacks (EUF-CMA) unter der RSA-Annahme.cite-ref-br96-1-1[1]

RSA-PSS ist in einer Variante im PKCS#1 ab Version 2.1 standardisiert. Insbesondere wird in diesem Standard die Nachricht zuerst gehasht; dies soll den Einsatz von Smartcards mit geringer Bandbreite als Signaturkarten ermΓΆglichen.cite-ref-pkcs21-2-0[2]

RSA-PSS ist Teil des großen Herstellerstandard Public-Key Cryptography Standards (PKCS), welcher schrittweise in Request for Comments (RFC) überführt wurde. Die Weiterentwicklung von RSAPSS erfolgt nur noch über RFC-Verâffentlichungen.

Normen und Standards

β€’ RFC: 8017 – Public-Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.2. 2016 (englisch).
β€’ RFC: 4056 – Use of the RSASSA-PSS Signature Algorithm in Cryptographic Message Syntax (CMS). 2005 (englisch).
β€’ RFC: 5756 – Updates for RSAES-OAEP and RSASSA-PSS Algorithm Parameters. 2010 (Konvention fΓΌr X.509 Zertifikate, englisch).

Einzelnachweise

cite-note-br96-11. ↑ Mihir Bellare, Phillip Rogaway: The exact security of digital signatures: How to sign with RSA and Rabin. In: Advances in Cryptology – EUROCRYPT 96 (= Lecture Notes in Computer Science). Band 1070. Springer, 1996, S. 399–416 (ucdavis.edu).
cite-note-pkcs21-22. ↑ RSA Laboratories (Hrsg.): PKCS #1 v2.1: RSA Cryptography Standard. 2002 (rsasecurity.com [PDF]).