On the use of RSA as a secret key cryptosystem (Q5931258)

From MaRDI portal

!

This is the item page for this Wikibase entity, intended for internal use and editing purposes. Please use the normal view instead:

scientific article; zbMATH DE number 1590771
Language Label Description Also known as
default for all languages
No label defined
    English
    On the use of RSA as a secret key cryptosystem
    scientific article; zbMATH DE number 1590771

      Statements

      On the use of RSA as a secret key cryptosystem (English)
      0 references
      0 references
      29 July 2002
      0 references
      Typically, symmetric and public key cryptosystems are based on different algorithms that use different functions. As sometimes some restrictions on computing area and memory apply (e.g. smart cards), an interesting task is to investigate the possibility to have the different cryptosystems make use of the same cryptographic primitives in their definition. Following this line of reasoning, the paper is aimed at exploring ways in which primitives usually associated with public key cryptosystems can be used in a symmetric key environment. It turns out that while use of such primitives in a secret key setting allows one to use smaller integers than in public key cryptosystems, one needs to carefully take into account other security issues. For example the homomorphic property of RSA makes its direct use as a secret key cryptosystem vulnerable to a chosen plaintext attack. It follows that one needs to use the basic primitives slightly differently. In the paper, first a general scheme is described that makes use of modular exponentiation in its encryption and decryption processes. Its design principles are then discussed and shown how potentially exploitable properties of the primitive are obfuscated. Subsequently, a more practical example of the cryptosystem is presented and its design principles are discussed and compared with the original one. The new system uses shorter keys than the previous one, but both have a certain amount of data expansion. The next section thus presents a way to reduce the data expansion, making previous cryptosystems more attractive from the practical point of view. The final section then brings some concluding remarks.
      0 references
      0 references
      RSA
      0 references
      modular exponentiation
      0 references
      unidirectional keys
      0 references
      cryptographic primitives
      0 references
      secret key cryptosystem
      0 references

      Identifiers