首页> 外文会议>European symposium on research in computer security >Server-Supported RSA Signatures for Mobile Devices
【24h】

Server-Supported RSA Signatures for Mobile Devices

机译:服务器支持的移动设备RSA签名

获取原文

摘要

We propose a new method for shared RSA signing between the user and the server so that: (a) the server alone is unable to create valid signatures; (b) having the client's share, it is not possible to create a signature without the server; (c) the server detects cloned client's shares and blocks the service; (d) having the password-encrypted client's share, the dictionary attacks cannot be performed without alerting the server; (e) the composite RSA signature "looks like" an ordinary RSA signature and verifies with standard crypto-libraries. We use a modification of the four-prime RSA scheme of Damgard, Mikkelsen and Skeltved from 2015, where the client and the server have independent RSA private keys. As their scheme is vulnerable to dictionary attacks, in our scheme, the client's RSA private exponent is additively shared between server and client. Our scheme has been deployed and has over 200,000 users.
机译:我们为用户和服务器之间的共享RSA签名提出了一种新方法,以便:(a)仅服务器无法创建有效签名; (b)拥有客户的份额,没有服务器就无法创建签名; (c)服务器检测到克隆的客户端共享并阻止该服务; (d)具有密码加密的客户端共享,在不通知服务器的情况下无法进行字典攻击; (e)复合RSA签名“看起来像”普通RSA签名,并通过标准加密库进行验证。我们从2015年起对Damgard,Mikkelsen和Skeltved的四个主要RSA方案进行了修改,其中客户端和服务器具有独立的RSA私钥。由于他们的方案容易受到字典攻击,因此在我们的方案中,服务器和客户端之间会加分共享客户端的RSA私有指数。我们的方案已经部署,拥有超过200,000个用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号