[Resource Topic] 2003/245: A Key Substitution Attack on SFLASH^{v3}

Welcome to the resource topic for 2003/245

A Key Substitution Attack on SFLASH^{v3}

Authors: Willi Geiselmann, Rainer Steinwandt


A practical key substitution attack on SFLASH^{v3} is described: Given a valid (message, signature) pair (m,\sigma) for some public key v_0, one can derive another public key v_1 (along with matching secret data) such that (m,\sigma) is also valid for v_1. The computational effort needed for finding such a `duplicate’ key is comparable to the effort needed for ordinary key generation.

ePrint: https://eprint.iacr.org/2003/245

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .