Cryptanalysis of Certain Variants of Rabin's Signature Scheme

Abstract Rabin's signature scheme is known to be susceptible to chosen cleartext attacks, and thus it is essential to perturb each message before it is signed. In this paper we show that certain natural perturbation techniques (including the addition of random prefixes or suffixes to the message) do not fully protect the scheme against a new type of chosen cleartext attack.