<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">7</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/8rnd-8vte-brfu</article-id>
      <title-group>
        <article-title>On the practicality of attacks on electronic document management systems when signature keys are jointly used in TLS 1.2</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>О практической реализуемости атак на системы электронного документооборота при использовании ключа подписи в протоколе TLS 1.2</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-6674-4374</contrib-id>
          <name>
            <surname>Mesengiser</surname>
            <given-names>Yakob</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>myy@cryptopro.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000–0002–1279–0359</contrib-id>
          <name>
            <surname>Alekseev</surname>
            <given-names>Evgeny</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>alekseev@cryptopro.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0003-4000-1174</contrib-id>
          <name>
            <surname>Kyazhin</surname>
            <given-names>Sergey</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
          <email>snkyazhin@mephi.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-8586-5959</contrib-id>
          <name>
            <surname>Smyshlyaev</surname>
            <given-names>Stanislav</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>svs@cryptopro.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Crypto-Pro LLC</aff>
      <aff id="aff2">National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-12-26">
        <day>26</day>
        <month>12</month>
        <year>2025</year>
      </pub-date>
      <issue>4</issue>
      <fpage>89</fpage>
      <lpage>101</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/pib_4.pdf"/>
      <abstract xml:lang="en">
        <p>Prohibiting the use of identical keys in different cryptographic algorithms and protocols is a prerequisite for the security of a wide variety of information systems. However, developers of such systems sometimes ignore this requirement since underestimate the threat. This paper addresses practical attack scenarios against electronic document management systems in a situation where the signature key is also used for client authentication in the TLS 1.2 protocol. As a result of one of the attacks, an adversary forms a signature for a selected PDF file up to 16 MB in size, which is correctly displayed by a number of popular applications. An analysis of the reasons for the feasibility of these attacks leads to the conclusion that a property exists in the TLS 1.2 protocol that leads to a vulnerability when the client authentication key is used as a signature key in electronic document management systems.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Cryptography</kwd>
        <kwd>digital signature</kwd>
        <kwd>TLS</kwd>
        <kwd>authentication</kwd>
        <kwd>joint using of a single key</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
