# GMR – signature system



## GMR – signature system

GMR – signature system (3) Problem: intermediate results of the tests are valid signatures for the start section of the message m Idea: coding the message prefix free Def. A mapping : M � M is called prefix free iff � m 1,m 2 � M: � b � {0,1} + : b � injective Example for a prefix free mapping 0 � 00 ; 1 � 11 ; end identifier 10 Prefix-free encoding should be efficient to calculate both ways. 201

To factor is difficult (1) Theorem: If factoring is difficult, then collision-resistant permutation pairs exist Proof: secret: p�q = n ; p � 83 und q � 87 (Blum numbers) -1 it holds: = 1 n f 0 (x) := f 1 (x) := 2 n = -1 x 2 mod n , if < -x 2 mod n , else (2x) 2 mod n, if < -(2x) 2 mod n, else -1 � QR n Domain : {x � Z * x n n | =1 , 0 < x < } n 2 n 2 n 2 - + n 202 n n -n 0 n 2 2

