0Pricing
Cryptology Academy · Lesson

RSA-PSS for Digital Signatures

Learn PSS encoding, salt, and why it replaced PKCS#1 v1.5 for signing.

RSA-PSS for Digital Signatures is a free Cryptology Academy lesson on CoddyKit — lesson 4 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cryptology Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Welcome

RSA-PSS (Probabilistic Signature Scheme) is the secure replacement for PKCS#1 v1.5 signatures. It uses randomized encoding for provably secure signatures.

PKCS#1 v1.5 Signature Weaknesses

PKCS#1 v1.5 signatures use a deterministic DigestInfo encoding. Known forgery attacks exploit loose verification implementations. Bleichenbacher (2006) showed signature forgeries against certain verifiers.

PSS Design Goals

Bellare-Rogaway 1996: PSS adds a random salt to make signatures probabilistic. Each signing produces a different signature. Provably secure in the random oracle model — tight reduction to RSA hardness.

PSS Encoding Steps

1. mHash = Hash(M) 2. salt = random(sLen bytes) 3. M' = 0x00×8 || mHash || salt 4. H = Hash(M') 5. DB = PS || 0x01 || salt 6. dbMask = MGF1(H, emLen - hLen - 1) 7. maskedDB = DB XOR dbMask 8. EM = maskedDB || H || 0xbc

Salt Length Choices

PKCS#1 v2.2 options: - MAX_LENGTH: salt as long as hash (recommended, maximum security) - DIGEST_LENGTH: salt = hash length (standard) - 0: deterministic PSS (loses probabilistic property, not recommended) Python: padding.PSS.MAX_LENGTH

PSS Verification

Recover EM = sig^e mod n. Parse maskedDB and H. Compute M' from mHash (from message) and recovered salt. Verify H == Hash(M'). The salt doesn't need to match — just H needs to verify.

PSS vs v1.5 Security Comparison

PSS: provably secure, tight reduction, probabilistic signatures, slightly larger computation. v1.5: heuristically secure, deterministic, faster, vulnerable to format oracle attacks. All new code should use PSS.

PSS in TLS 1.3

TLS 1.3 requires RSA-PSS for all RSA signatures. PKCS#1 v1.5 is prohibited in new TLS 1.3 extensions. Signature algorithms: rsa_pss_rsae_sha256, rsa_pss_rsae_sha384, rsa_pss_rsae_sha512.

PSS in Python

from cryptography.hazmat.primitives.asymmetric import padding from cryptography.hazmat.primitives import hashes # Sign sig = private_key.sign( message, padding.PSS(mgf=padding.MGF1(hashes.SHA256()), salt_length=padding.PSS.MAX_LENGTH), hashes.SHA256() )

RSASSA-PSS OID

RSA-PSS has its own key type OID: id-RSASSA-PSS (1.2.840.113549.1.1.10). Keys generated specifically for PSS use this OID and require PSS signing (won't work with v1.5). Best practice for new deployments.

Truncated Hashes and Salt Recommendations

Security of PSS = min(|modulus|/2, |hash|) - 1 bits when salt_length = hash_length. For RSA-2048 with SHA-256: 128-bit security. Match security level: RSA-3072 + SHA-384 for 192-bit security.

Quick Check

What makes RSA-PSS signatures 'probabilistic' compared to PKCS#1 v1.5?

Recap

RSA-PSS is the secure way to sign with RSA. Next we master elliptic curve cryptography — understanding the geometry and algebra of curves.

Frequently asked questions

Is the “RSA-PSS for Digital Signatures” lesson free?

Yes — the full text of “RSA-PSS for Digital Signatures” is free to read here on the web, and the Cryptology Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cryptology Academy course, upgrade to CoddyKit PRO.

What will I learn in “RSA-PSS for Digital Signatures”?

Learn PSS encoding, salt, and why it replaced PKCS#1 v1.5 for signing. You practise Cryptology Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cryptology Academy?

No prior experience is required. Cryptology Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 4 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “RSA-PSS for Digital Signatures” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cryptology Academy lesson?

Yes. Every Cryptology Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Textbook RSA & Why It Is Insecure
  2. PKCS#1 v1.5 Padding & Bleichenbacher
  3. OAEP: Optimal Asymmetric Encryption Padding
  4. RSA-PSS for Digital Signatures
← Back to Cryptology Academy