The design and analysis of protocols that protect information or authenticate messages in the presence of adversaries. It includes ciphers, digital signatures and cryptographic hash functions.
Assurance of the source and integrity of a message against specified adversarial capabilities. Digital signatures permit public verification, whereas a message authentication code uses a shared secret; encryption alone need not authenticate.
A keyed function producing a tag that a holder of the shared secret can verify. Its message authentication security requires that valid tags for new messages cannot be forged under the allowed adversarial queries. Unlike a digital signature, verification is not inherently public and the verifier also knows a key capable of making tags.
A protocol value intended to be used only once under a specified key. In the ElGamal signature scheme the signing nonce must also be secret and invertible modulo the group order; mere distinctness does not imply unpredictability.
Cryptography using a public key and a corresponding private key. Public-key encryption lets others encrypt for the private-key holder; a digital signature instead lets the holder authenticate messages for public verification.
The published member of a public-key cryptographic key pair. Its association with a particular identity must itself be authenticated; mere knowledge of a purported public key does not establish that identity.
The secret member of a public-key cryptographic key pair, used for decryption or signing according to the scheme. In the RSA cryptosystem the private exponent is not interchangeable with a security proof for textbook signing.
The transformation of a message into a ciphertext using a key, with decryption recovering the message using an appropriate key. Confidentiality and message authentication are separate properties; an encryption scheme needs explicit security hypotheses.
An attack in which an adversary obtains decryptions of selected ciphertexts, subject to the protocol’s restrictions. The multiplicative structure of textbook RSA cryptosystem permits blinding an intercepted ciphertext by a known invertible factor.
A function mapping messages of arbitrary length to fixed-length digests, designed to provide preimage resistance and collision resistance. In a digital signature protocol the digest also needs an encoding and security properties appropriate to that protocol.
Finding any distinct messages with equal cryptographic hash values should be computationally infeasible under the specified security model. A collision can let a signed digest authenticate an unintended message.
Given a target digest h, finding a message m with H(m)=h should be computationally infeasible under the specified security model. This is distinct from finding two messages with equal digests.
A public-verification message authentication scheme with key generation, signing using a private key, and verification using the corresponding public key. Signing an appropriate digest binds the signature to the message; encryption alone does not provide this authenticity.
For a prime number , primitive root and public key , choose a fresh secret coprime to , set and , and verify . Reusing the cryptographic nonce can reveal secret information. The unhashed historical construction allows existential forgery of specially chosen message exponents, so authentication claims require suitable hashing and protocol assumptions.
A signature based on private RSA cryptosystem exponentiation, with public exponentiation used for verification. Textbook is multiplicatively forgeable; a secure scheme requires an appropriate encoding and message digest rather than raw message exponentiation.

Articles by others on the same topic (2)

Cryptography is the practice and study of techniques for securing communication and information by transforming it into a format that is unreadable to unauthorized users. It involves creating systems and methods to protect the confidentiality, integrity, authenticity, and non-repudiation of data. Here are some key aspects of cryptography: 1. **Confidentiality**: Ensures that information is only accessible to those authorized to view it. This is commonly achieved through encryption, which converts plaintext into ciphertext.