As with RSA the security of the system is related to the difficulty of factoring very large numbers. But, in contrast to RSA, GMR is secure against adaptive chosen-message attacks — even when an attacker receives signatures for messages of his choice, this does not allow him to forge a signature for a single additional message.
- A Digital Signature Scheme Secure Against Adaptive Chosen-Message Attacks - Shafi Goldwasser, Silvio Micali, Ronald L. Rivest
|This cryptography-related article is a stub. You can help Wikipedia by expanding it.|