网络安全技术电信群楼3-509
网络安全技术 电信群楼3-509 1
Digital SignatureHash Function Authentication CodeMessage
Digital Signature Hash Function Message Authentication Code 2
Digital SignatureThereisanelectronicdocumenttobesentfromAlicetoBobIs there a functional equivalenceto a handwrittensignature?EasyforAlicetosignonthedocument口But hard for anyoneelse to forge口EasyforBoboranyonetoverifyAnswer:digital signatureMessageSignatureSignusingAlice'sprivatekey口VerifyusingAlice'spublickeyVerifyPublickeyPrivatekeySignMessagepeeValid/Invalid(fixed-length signature)Onlythesigner(whohasaprivatekey)cangenerateavalidsignatureAnyone (sincethecorrespondingpublickeyispublished)canverifyifasignature with respect to a message is valid3
Digital Signature ◼ There is an electronic document to be sent from Alice to Bob. ◼ Is there a functional equivalence to a handwritten signature? ❑ Easy for Alice to sign on the document ❑ But hard for anyone else to forge ❑ Easy for Bob or anyone to verify ◼ Answer: digital signature ❑ Sign using Alice’s private key ❑ Verify using Alice’s public key ❑ Only the signer (who has a private key) can generate a valid signature ❑ Anyone (since the corresponding public key is published) can verify if a signature with respect to a message is valid Message Sign rfwekfs Private key (fixed-length signature) Public key Verify Message Signature Valid/Invalid 3
RSA Signature SchemeSetup:n = pq where p, q are large prime (say 512 bits long each)口ed = 1 mod (p-1)(q-1)口Signing (Private) Key : d口Verification (Public) Key : (e, n)7Signature Generation:S=MdmodnwhereMissomemessageSignature Verification: If Se mod n = M, output valid; otherwise, output invalid
RSA Signature Scheme ◼ Setup: ❑ n = pq where p, q are large prime (say 512 bits long each) ❑ ed = 1 mod (p-1)(q-1) ❑ Signing (Private) Key : d ❑ Verification (Public) Key : (e, n) ◼ Signature Generation: ❑ S = Md mod n where M is some message ◼ Signature Verification: ❑ If Se mod n = M, output valid; otherwise, output invalid 4
Hash Function MotivationConsider the RSA Signature Scheme, if M > n, howto sign M?Solution: instead of signing M directly, Alice signs ahash of M denoted by h(M) Alice sends M and S = Sign(SKAlice, h(M) to Bob Bob verifies that Verify(PKAlice, h(M), S) = validh is called a hash functionh maps a binary string to a non-zero integer smallerthan nh(M) is called the message digest5
Hash Function Motivation ◼ Consider the RSA Signature Scheme, if M > n, how to sign M? ◼ Solution: instead of signing M directly, Alice signs a hash of M denoted by h(M) ❑ Alice sends M and S = Sign(SKAlice, h(M)) to Bob ❑ Bob verifies that Verify(PKAlice, h(M), S) = valid ◼ h is called a hash function ◼ h maps a binary string to a non-zero integer smaller than n ◼ h(M) is called the message digest 5