January 15, 2002
Practical Aspects of Modern Cryptography
RSA Signatures
•An additional property
• D(E(Y)) = YED mod N = Y
• E(D(Y)) = YDE mod N = Y
•Only Alice (knowing the factorization of N) knows D.  Hence only Alice can compute D(Y) = YD mod N.
•This D(Y) serves as Alice’s signature on Y.