Notions of Security
In their foundational paper, Goldwasser, Micali, and Rivest lay out a hierarchy of attack models against digital signatures:
- In a key-only attack, the attacker is only given the public verification key.
- In a known message attack, the attacker is given valid signatures for a variety of messages known by the attacker but not chosen by the attacker.
- In an adaptive chosen message attack, the attacker first learns signatures on arbitrary messages of the attacker's choice.
They also describe a hierarchy of attack results:
- A total break results in the recovery of the signing key.
- A universal forgery attack results in the ability to forge signatures for any message.
- A selective forgery attack results in a signature on a message of the adversary's choice.
- An existential forgery merely results in some valid message/signature pair not already known to the adversary.
The strongest notion of security, therefore, is security against existential forgery under an adaptive chosen message attack.
Read more about this topic: Digital Signature
Famous quotes containing the words notions of, notions and/or security:
“Your notions of friendship are new to me; I believe every man is born with his quantum, and he cannot give to one without robbing another. I very well know to whom I would give the first place in my friendship, but they are not in the way, I am condemned to another scene, and therefore I distribute it in pennyworths to those about me, and who displease me least, and should do the same to my fellow prisoners if I were condemned to a jail.”
—Jonathan Swift (16671745)
“The herd of mankind can hardly be said to think; their notions are almost all adoptive; and, in general, I believe it is better that it should be so; as such common prejudices contribute more to order and quiet, than their own separate reasonings would do, uncultivated and unimproved as they are.”
—Philip Dormer Stanhope, 4th Earl Chesterfield (16941773)
“Thanks to recent trends in the theory of knowledge, history is now better aware of its own worth and unassailability than it formerly was. It is precisely in its inexact character, in the fact that it can never be normative and does not have to be, that its security lies.”
—Johan Huizinga (18721945)