On the Security of RSA Screening [chapter]

Jean -Sebastien Coron, David Naccache
1999 Lecture Notes in Computer Science  
Since many applications require the verification of large sets of signatures, it is sometimes advantageous to perform a simultaneous verification instead of checking each signature individually. The simultaneous processing, called batching, must be provably equivalent to the sequential verification of all signatures. In eurocrypt'98, Bellare et al. [1] presented a fast RSA batch verification scheme, called screening. Here we successfully attack this algorithm by forcing it to accept a false
more » ... ature and repair it by implementing an additional test.
doi:10.1007/3-540-49162-7_15 fatcat:ndbdhym6drdw5iv4hkik5rd36u