Bauer-Berson-Feiertag attack revisited

We show that Shoup and Rubin’s protocols are not secure against the BBF attack proposed by Bauer, Berson, and Feiertag, and propose an amendment. Furthermore, our results indicate that both Bellare and Rogaway’s security and Paulson’s security do not imply the security against the BBF attack.