January 15, 2002
Practical Aspects of Modern Cryptography
RSA Signatures
•
An additional property
•
D(E(Y)) = Y
ED
mod N = Y
•
E(D(Y)) = Y
DE
mod N = Y
•
Only Alice (knowing the factorization of
N
)
knows
D
.
Hence only Alice can compute
D(Y) = Y
D
mod N
.
•
This
D(Y)
serves as Alice’s signature on
Y
.