Journal of Computer Applications

• Information security • Previous Articles     Next Articles

Cryptanalysis and improvement of certificateless proxy signature scheme

Chen-Huang WU Zhi-xiong CHEN Hai-ming WANG Yi-jun SHEN   

  • Received:2008-10-22 Revised:2008-12-03 Online:2009-04-01 Published:2009-04-01
  • Contact: Chen-Huang WU

一个无证书代理签名方案的安全性分析及改进

吴晨煌 陈智雄 王海明 沈毅军   

  1. 福建省莆田学院 福建省莆田学院 福建省莆田学院 福建省莆田学院
  • 通讯作者: 吴晨煌

Abstract: The certificateless proxy signature scheme proposed by Fan Rui etc. was analyzed and their scheme turned out to be insecure. Furthermore, a serious security flaw was discovered in the proxy key generation algorithm, because the private key of the original signer could be recovered by the proxy signer. Unfortunately, the same security flaw was also found out in other proxy signature schemes. Finally, a comprehensive and improved scheme was proposed, whose security was based on the Computational Diffie-Hellman Problem (CDHP).

Key words: certificateless, proxy, digital signature, public key replacement attack, bilinear pairings

摘要: 通过对樊睿等人提出的无证书代理签名方案进行分析,指出了该方案是不安全的。同时该方案的代理密钥生成算法由于代理签名人能够得到原始签名人的私钥,存在严重的安全缺陷,并指出同样的安全缺陷也存在于另外几个的代理签名方案中。最后,对该签名方案进行了全面改进,改进后方案的安全性是基于计算Diffie-Hellman问题。

关键词: 无证书, 代理, 数字签名, 替换公钥攻击, 双线性对

CLC Number: