January 15, 2002
Practical Aspects of Modern Cryptography
RSA Cautions
•
D(Y
1
)
• D(Y
2
) = D(Y
1
• Y
2
)
•
•
Thus, if I’ve decrypted (or signed)
Y
1
and
Y
2
,
I’ve also decrypted (or signed)
Y
1
• Y
2
.