{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,21]],"date-time":"2026-03-21T19:47:42Z","timestamp":1774122462514,"version":"3.50.1"},"publisher-location":"Berlin, Heidelberg","reference-count":21,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540693277","type":"print"},{"value":"9783540693284","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11967668_3","type":"book-chapter","created":{"date-parts":[[2007,2,6]],"date-time":"2007-02-06T07:03:43Z","timestamp":1170745423000},"page":"31-48","source":"Crossref","is-referenced-by-count":14,"title":["Impossibility Proofs for RSA Signatures in the Standard Model"],"prefix":"10.1007","author":[{"given":"Pascal","family":"Paillier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/978-3-540-24676-3_11","volume-title":"Advances in Cryptology - EUROCRYPT 2004","author":"M. Bellare","year":"2004","unstructured":"Bellare, M., Boldyreva, A., Palacio, A.: An uninstantiable random-oracle-model scheme for a hybrid-encryption problem. In: Cachin, C., Camenisch, J.L. (eds.) EUROCRYPT 2004. LNCS, vol.\u00a03027, pp. 171\u2013188. Springer, Heidelberg (2004)"},{"issue":"3","key":"3_CR2","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/s00145-002-0120-1","volume":"16","author":"M. Bellare","year":"2003","unstructured":"Bellare, M., Namprempre, C., Pointcheval, D., Semanko, M.: The One-More-RSA-Inversion Problems and the security of Chaum\u2019s Blind Signature Scheme. Journal of Cryptology\u00a016(3), 185\u2013215 (2003)","journal-title":"Journal of Cryptology"},{"key":"3_CR3","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1145\/168588.168596","volume-title":"ACM CCS 1993","author":"M. Bellare","year":"1993","unstructured":"Bellare, M., Rogaway, P.: Random oracles are practical: A paradigm for designing efficient protocols. In: ACM CCS 1993, pp. 62\u201373. ACM Press, New York (1993)"},{"key":"3_CR4","series-title":"Lecture Notes in Computer Science","first-page":"412","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"M. Fischlin","year":"2005","unstructured":"Fischlin, M., Boldyreva, A.: Analysis of Random Oracle Instantiation Scenarios for OAEP and Other Practical Schemes. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol.\u00a03621, pp. 412\u2013429. Springer, Heidelberg (2005)"},{"key":"3_CR5","unstructured":"Brown, D.R.L.: Unprovable security of RSA-OAEP in the standard model (2006), Available at: \n                    \n                      http:\/\/eprint.iacr.org\/2006\/223"},{"key":"3_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1007\/978-3-540-24638-1_3","volume-title":"Theory of Cryptography","author":"R. Canetti","year":"2004","unstructured":"Canetti, R., Goldreich, O., Halevi, S.: On the random-oracle methodology as applied to length-restricted signature schemes. In: Naor, M. (ed.) TCC 2004. LNCS, vol.\u00a02951, pp. 40\u201357. Springer, Heidelberg (2004)"},{"key":"3_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1007\/3-540-44598-6_14","volume-title":"Advances in Cryptology - CRYPTO 2000","author":"J.-S. Coron","year":"2000","unstructured":"Coron, J.-S.: On the exact security of full domain hash. In: Bellare, M. (ed.) CRYPTO 2000. LNCS, vol.\u00a01880, pp. 229\u2013235. Springer, Heidelberg (2000)"},{"key":"3_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"449","DOI":"10.1007\/11535218_27","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"Y. Dodis","year":"2005","unstructured":"Dodis, Y., Oliveira, R., Pietrzak, K.: On the Generic Insecurity of the Full Domain Hash. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol.\u00a03621, pp. 449\u2013466. Springer, Heidelberg (2005)"},{"key":"3_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"234","DOI":"10.1007\/3-540-48658-5_23","volume-title":"Advances in Cryptology - CRYPTO \u201994","author":"C. Dwork","year":"1994","unstructured":"Dwork, C., Naor, M.: An efficient existentially unforgeable signature scheme and its applications. In: Desmedt, Y.G. (ed.) CRYPTO 1994. LNCS, vol.\u00a0839, pp. 234\u2013246. Springer, Heidelberg (1994)"},{"key":"3_CR10","series-title":"Lecture Notes in Computer Science","first-page":"186","volume-title":"Advances in Cryptology - CRYPTO \u201986","author":"A. Fiat","year":"1987","unstructured":"Fiat, A., Shamir, A.: How to prove yourself: Practical solutions to identification and signature problems. In: Odlyzko, A.M. (ed.) CRYPTO 1986. LNCS, vol.\u00a0263, pp. 186\u2013194. Springer, Heidelberg (1987)"},{"issue":"2","key":"3_CR11","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"Goldwasser, S., Micali, S., Rivest, R.L.: A digital signature scheme secure against adaptive chosen-message attacks. SIAM Journal on Comp.\u00a017(2), 281\u2013308 (1988)","journal-title":"SIAM Journal on Comp."},{"key":"3_CR12","unstructured":"IEEE P1363a Committee. IEEE P1363a \/ D9 \u2014 Standard specifications for public key cryptography: Additional techniques (2001), Draft Version 9, Document available at: \n                    \n                      http:\/\/grouper.ieee.org\/groups\/1363\/index.html\/"},{"key":"3_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/3-540-45708-9_8","volume-title":"Advances in Cryptology - CRYPTO 2002","author":"J.B. Nielsen","year":"2002","unstructured":"Nielsen, J.B.: Separating random oracle proofs from complexity theoretic proofs: The non-committing encryption case. In: Yung, M. (ed.) CRYPTO 2002. LNCS, vol.\u00a02442, pp. 111\u2013126. Springer, Heidelberg (2002)"},{"key":"3_CR14","unstructured":"Paillier, P.: Instance-non-malleable RSA-based cryptography (2006), Available at: \n                    \n                      http:\/\/eprint.iacr.org\/2006\/"},{"key":"3_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11593447_1","volume-title":"Advances in Cryptology - ASIACRYPT 2005","author":"P. Paillier","year":"2005","unstructured":"Paillier, P., Vergnaud, D.: Discrete-log-based signatures may not be equivalent to discrete log. In: Roy, B. (ed.) ASIACRYPT 2005. LNCS, vol.\u00a03788, pp. 1\u201320. Springer, Heidelberg (2005)"},{"key":"3_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/11935230_17","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2006","author":"P. Paillier","year":"2006","unstructured":"Paillier, P., Villar, J.: Trading one-wayness against chosen-ciphertext security in factoring-based encryption. In: Lai, X., Chen, K. (eds.) ASIACRYPT 2006. LNCS, vol.\u00a04284, pp. 252\u2013266. Springer, Heidelberg (2006)"},{"key":"3_CR17","unstructured":"PKCS #1 v2.1: RSA cryptography standard (draft), RSA Data Security Inc. (September 2005), Document available at: \n                    \n                      http:\/\/www.rsasecurity.com\/rsalabs\/pkcs\/"},{"key":"3_CR18","unstructured":"Rabin, M.O.: Digital signatures and public key functions as intractable as factorization. Technical Report MIT\/LCS\/TR-212, MIT (January 1979)"},{"key":"3_CR19","unstructured":"Tompa, M., Woll, H.: Random self-reducibility and zero-knowledge interactive proofs of possession of information. UCSD TR CS92-244 (1992)"},{"issue":"6","key":"3_CR20","doi-asserted-by":"publisher","first-page":"726","DOI":"10.1109\/TIT.1980.1056264","volume":"IT-26","author":"H.C. Williams","year":"1980","unstructured":"Williams, H.C.: A modification of the RSA public-key encryption procedure. IEEE Transactions on Information Theory\u00a0IT-26(6), 726\u2013729 (1980)","journal-title":"IEEE Transactions on Information Theory"},{"key":"3_CR21","volume-title":"Malicious Cryptography: Exposing Cryptovirology","author":"A. Young","year":"2005","unstructured":"Young, A., Yung, M.: Malicious Cryptography: Exposing Cryptovirology, 1st edn. John Wiley & Sons, Chichester (2005)","edition":"1"}],"container-title":["Lecture Notes in Computer Science","Topics in Cryptology \u2013 CT-RSA 2007"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11967668_3.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T03:23:42Z","timestamp":1619493822000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11967668_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540693277","9783540693284"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/11967668_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006]]}}}