Hypothetical scenario:
- A user creates a public key
- An encrypted or signed payload exists.
- With only public key, and a signed payload, Mallory wants to find out who signed the data. We want to prevent Mallory from associating an encrypted payload to the public key.
I assume that most modern encryption primitives (GSM, AES, RSA) allow for this type of association, however, it's possible that some protocols (SMIME? PGP?) might disclose the signing key in the payload, even if the spec allows its omission.
Question
Can someone either tell me which crypto allows for plausible deniability, or conversely which ones do not?*
*I ask in this way to prevent a too broad close reason, because I'm not sure which is greater
Aucun commentaire:
Enregistrer un commentaire