00 || MD5-Hash(m) || 00 ... 00
(padded on the right with 00 up to the RSA modulus length).
I believe no signature standard implements this
(I checked with X9.31, PKCS #1, ISO 9796).
Is this the Bellare-Rogaway FDH scheme ?
(FDH=Full Domain Hashing).
Thanks for any clue.
What kind of signature scheme is this? An insecure one.
(Look for semi-smooth numbers, and exploit homomorphic properties.)
Ok, that was a little joke, but as far as I know, it's not a standard.
I sure hope it's not a standard. I seem to remember that an early
version of Digicash's ecash protocol may have used this scheme; If I
remember correctly, I think Ian Goldberg and I showed an attack, and
they changed it. Or maybe I'm hallucinating.
>Is this the Bellare-Rogaway FDH scheme ?
>(FDH=Full Domain Hashing).
Nope.