摘要
盲签名和代理多重签名在电子商务和电子现金系统中有着广泛的应用。结合这两种签名的特点,人们提出了代理盲多重签名方案。在代理盲多重签名中,一个原始签名组将签名权委托给代理签名人,由其对签名请求者发送来的盲化消息进行代理签名。通过分别对秦艳琳等人和周立章提出的代理盲多重签名方案的安全性分析,发现秦的方案中一个恶意的原始签名人可以伪造出代理签名密钥,从而生成代理盲多重签名;并同时指出周的方案无法抵挡代理签名伪造攻击,不满足不可伪造性。针对上述两种攻击,在秦方案的基础上提出了一种新的方案,证明及分析了新方案的正确性和安全性。该方案有效地克服了原方案的缺陷,并满足代理盲多重签名的各种要求,提高了系统的安全性。
Blind signature and proxy multi-signature are widely used in e-commerce and e-cash systems.Combining with the feature of two signatures,people propose the proxy blind multi-signature scheme.In proxy blind multi-signature,an original signer group delegates the signing power to a proxy signer,which can sign the blinded message sent by the signing requestor.Security analyses of two proxy blind multi-signature schemes proposed respectively by Qin et al.and Zhou are presented here.Qin et al.'s scheme can't resist the proxy signing key forgery attack from a malicious original signer who uses the forged proxy signing key to generate the proxy blind multi-signature.Zhou proposed another proxy blind multi-signature scheme also based on Elliptic Curve Cryptography.However,we find that a proxy signer can forge a proxy blind multi-signature without the delegation of original signer group.According to the above forgery attacks,a novel proxy blind multi-signature scheme based on Qin et al.'s scheme is proposed,and it proved to be much more correct and safer than the former scheme.
出处
《计算机与数字工程》
2012年第10期102-104,165,共4页
Computer & Digital Engineering