Hawkynt

Rabin-Williams

Rabin-Williams signature scheme with message recovery, following IEEE P1363 and Bernstein’s treatment of the e and f tweaks. Signing extracts a square root modulo n = p*q with p congruent 3 and q congruent 7 modulo 8; verification squares the root and applies the transmitted tweak. Security is equivalent to integer factorization.

Properties

Property Value
Category Asymmetric Ciphers
Sub-category Digital Signature Scheme
Security status 🎓 Educational Only
Complexity Advanced
Inventor Michael O. Rabin, Hugh C. Williams
Year 1979
Origin 🇺🇸 United States
Source algorithms/asymmetric/rabin-williams.js

Parameters

Parameter Supported values
Key sizes 1024 bytes (8192 bits); 2048 bytes (16384 bits)

Security

Status: 🎓 Educational Only

Known vulnerabilities

Issue Description Mitigation
Message Recovery Without Hashing — This variant recovers the message itself rather than a hash of it, so an attacker who can pick the representative can pick the message. Sign a hash of the message under a collision resistant function for any use beyond demonstration
Published Demonstration Keys — The key pairs in this file are printed in the source, so anyone can forge under them. Supply real key material through the publicKey/privateKey properties for any use beyond demonstration

Documentation

References

Test vectors

2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 — Rabin-Williams Round-trip Test - IEEE P1363 Compliance

Field Value
key 0400
input 48656c6c6f20576f726c64
expected 48656c6c6f20576f726c64

Vector 2 — Rabin-Williams-2048 recovery of a message with leading zero octets

Field Value
key 0800
input 0000000102030405
expected 0000000102030405

← All algorithms