Consider a variant of DSA in which the message space is Z_q and H is omitted. (So the second component of the signature is now s = [k^-1 · (m + xr) mod q]) Show that this variant is not secure.
Added by Samantha B.
Close
Step 1
In the original DSA, the signature is a pair (r, s) where r = (g^k mod p) mod q and s = k^(-1) * (H(m) + x * r) mod q. Show more…
Show all steps
Your feedback will help us improve your experience
Adi S and 71 other Calculus 3 educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Textbooks
Calculus: Early Transcendentals
Thomas Calculus
Transcript
600,000+
Students learning Calculus with Numerade
Trusted by students at 8,000+ universities
Watch the video solution with this free unlock.
EMAIL
PASSWORD