The GATE Grind

GATE 2017 CS – Question 25

Computer Networks · Application Layer: DNS and HTTP · 1 mark · Multiple choice

A sender S sends a message $m$ to receiver R, which is digitally signed by S with its private key. In this scenario, one or more of the following security violations can take place.

(I) S can launch a birthday attack to replace $m$ with a fraudulent message.

(II) A third party attacker can launch a birthday attack to replace $m$ with a fraudulent message.

(III) R can launch a birthday attack to replace $m$ with a fraudulent message.

Which of the following are possible security violations?

  1. (I) and (II) only
  2. (I) only
  3. (II) only
  4. (II) and (III) only

Practise this question in The GATE Grind →

Show answer and explanation

Correct answer: (B) (I) only

Explanation

A birthday attack finds two different messages with the same hash. The attacker needs the signer to sign a harmless message that shares its hash with a fraudulent one. Only the signer, S, can arrange that, by preparing both versions and later claiming the fraudulent one was signed. A third party or the receiver cannot make S sign the harmless version, so only (I) is possible.