English

Attacking the Diebold Signature Variant -- RSA Signatures with Unverified High-order Padding

Cryptography and Security 2024-03-15 v2

Abstract

We examine a natural but improper implementation of RSA signature verification deployed on the widely used Diebold Touch Screen and Optical Scan voting machines. In the implemented scheme, the verifier fails to examine a large number of the high-order bits of signature padding and the public exponent is three. We present an very mathematically simple attack that enables an adversary to forge signatures on arbitrary messages in a negligible amount of time.

Keywords

Cite

@article{arxiv.2403.01048,
  title  = {Attacking the Diebold Signature Variant -- RSA Signatures with Unverified High-order Padding},
  author = {Ryan W. Gardner and Tadayoshi Kohno and Alec Yasinsac},
  journal= {arXiv preprint arXiv:2403.01048},
  year   = {2024}
}