摘要
现在许多无证书签名方案过度依赖于密钥生成中心(KGC)的诚实性,所以当KGC失去诚信的时候这些方案也就失去了安全保证。通过对梁红梅等人(梁红梅,黄振杰.高效无证书签名方案的安全性分析与改进.计算机应用,2010,30(3):685-687)提出的无证书签名方案进行安全性分析,指出其方案不可抵抗消极不诚实KGC下的公钥替换攻击和积极不诚实的KGC攻击。针对该问题,采用由KGC生成用户公钥并公开的方法,对原方案进行了改进。安全性分析表明,改进后的方案可抵抗消极不诚实KGC下的公钥替换攻击,判别KGC的积极不诚实性行为和在随机预言机模型下可抵抗适应性选择消息攻击下的存在性伪造。
Nowadays,many centificateless signature schemes depend on the honesty of Key Generation Center(KGC) excessively,so they also lose security guarantees when the KGC is dishonest.By analyzing the security of the certificateless signature scheme proposed by Liang Hongmei et.al.in security analysis and improvement of efficient certificateless signature scheme publicated by Journal fo Computer Applications,2010,30(3):685-687,where the authors pointed out that the scheme could not resist public key replacement attack under negative dishonest KGC and positive dishonest KGC's attacks.Aiming at these problems,the scheme was improved by the means that KGC generated the user's public key and made it public.The analysis of security shows that the improved scheme is able to resist public key replacement attack under negative dishonest KGC,thus successfully distinguishing the positive dishonesty of KGC,and resisting existential forgery on adaptively chosen message attack under the random oracle model.
出处
《计算机应用》
CSCD
北大核心
2011年第6期1536-1538,共3页
journal of Computer Applications