RUS  ENG
Full version
JOURNALS // Matematicheskie Voprosy Kriptografii [Mathematical Aspects of Cryptography] // Archive

Mat. Vopr. Kriptogr., 2022 Volume 13, Issue 2, Pages 53–64 (Mi mvk408)

Security properties of one “short” signature scheme

A. M. Guselev

Technical committee on standardization "Cryptography and Security Mechanisms" (TC 26), Moscow

Abstract: At CTCrypt 2020 workshop a "short" digital signature scheme was presented. The scheme was made up by three modifications of the scheme described in GOST R 34.10-2012. The security of the "short" signature scheme was considered from the provable security point of view. However no practical variants to attack the scheme were presented, the particular level of bit security was not estimated. In this article we discuss the influence of signature shortening on the security of suggested schemes. Several attacks based on the modifications are presented. Characteristics of the attacks are used to estimate the bit security of the "short" signature scheme.

Key words: digital signature scheme, security level evaluation.

UDC: 519.719.2

Received 14.XI.2021

Language: English

DOI: 10.4213/mvk408



Bibliographic databases:


© Steklov Math. Inst. of RAS, 2024