[cryptography] RSA signatures without padding

Alexandre Anzala-Yamajako anzalaya at gmail.com
Fri Jul 10 17:25:46 EDT 2015


This paper probably helps answering part of your question :
http://www.iacr.org/archive/crypto2000/18800229/18800229.pdf
Note that you can't replace a random oracle by SHA256 but you might have
better luck with HMAC-SHA256 (https://eprint.iacr.org/2013/382.pdf)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.randombit.net/pipermail/cryptography/attachments/20150710/5c46c832/attachment.html>


More information about the cryptography mailing list