Zhihua Xiong, Yixin Xu, et al.
International Journal of Modelling, Identification and Control
We describe two different attacks against the ISO/IEC 9796-1 signature standard for RSA and Rabin. Both attacks consist in an existential forgery under a chosen-message attack: the attacker asks for the signature of some messages of his choice, and is then able to produce the signature of a message that was never signed by the legitimate signer. The first attack is a variant of Desmedt and Odlyzko's attack and requires a few hundreds of signatures. The second attack is more powerful and requires only three signatures. © 2007 International Association for Cryptologic Research.
Zhihua Xiong, Yixin Xu, et al.
International Journal of Modelling, Identification and Control
Guo-Jun Qi, Charu Aggarwal, et al.
IEEE TPAMI
Arnon Amir, Michael Lindenbaum
IEEE Transactions on Pattern Analysis and Machine Intelligence
Renu Tewari, Richard P. King, et al.
IS&T/SPIE Electronic Imaging 1996