摘要
对一个改进的无证书代理签名方案进行了安全性分析,指出了该改进方案对公钥替换攻击是脆弱的。详细给出了公钥替换攻击方法,即对任意选择的消息和授权书,敌手通过替换原始签名者和代理签名者的公钥来伪造该消息的代理签名。分析表明,该改进方案不满足无证书代理签名的安全性质。针对这种公钥替换攻击,提出了一个新的改进方案。
An improved certificateless proxy signature scheme is analyzed and it points out that the improved certificateless proxy signature scheme is vulnerable under the public key replacement attack.The attack method is given in details and it shows that the adversary can forge the proxy signature for any message and any warrant by substituting the public keys of original signers and proxy signers.The analysis shows that the improved scheme does not satisfy the properties of the certificateless proxy signature.A new improved scheme is proposed to resist the above attack.
出处
《武汉理工大学学报》
CAS
CSCD
北大核心
2011年第2期153-156,共4页
Journal of Wuhan University of Technology
基金
国家自然科学基金(60703048)
湖北省自然科学基金(2007ABA313)
关键词
无证书密码学
代理签名
公钥替换攻击
双线性对
certificateless cryptography
proxy signature
public key replacement attack
bilinear pairing