03.08.2013 Views

M - Technische Universität Dresden

M - Technische Universität Dresden

M - Technische Universität Dresden

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Breaking the direct RSA-implementation of MIXes (2)<br />

Let the identifiers z‘ and M‘ be defined by<br />

(z,M)•f ≡ z‘•2 B + M‘ ⇒<br />

z•2 B •f + M•f ≡ z‘•2 B + M‘ ⇒<br />

2 B • (z•f - z‘) ≡ M‘ - M•f ⇒<br />

z•f - z‘ ≡ (M‘ - M•f) • (2 B ) -1 (1)<br />

If the attacker chooses f ≤ 2 b , it holds<br />

–2 b < z•f - z‘ < 2 2b (2)<br />

The attacker replaces in (1) M and M‘ by all output-message pairs of the<br />

batch and tests (2).<br />

(2) holds, if b

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!