Attack on Chen et al.'s certificateless aggregate signature scheme

Attack on Chen et al.'s certificateless aggregate signature scheme
复制标题

DOI:
10.1002/sec.1380
复制
发表时间:
2016-01
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Jianhong Zhang;Xubing Zhao;Jian Mao
Jianhong Zhang;Xubing Zhao;Jian Mao
中科院分区:
其他
文献类型:
--
作者:
Jianhong Zhang;Xubing Zhao;Jian Mao

文献摘要

被引文献

相似文献

无证书聚合签名可以有效地验证来自不同用户的大量签名。这个特性使得它在低带宽通信、低存储和低可计算性的环境中非常有用。最近,Chen等人提出了一种新的无证书聚合签名方案。他们声称他们的方案在计算Diffie-Hellman问题下是可证明安全的。不幸的是,本文证明了Chen等人的方案是不安全的,它不能抵抗I型和II型对手,并给出了相应的攻击。此外,我们还证明了他们的方案存在更强大的攻击,即任何人都可以在此攻击中对任意消息伪造无证书签名。最后讨论了此类攻击产生的原因,并给出了相应的抵制此类攻击的建议。版权所有©2015 John Wiley & Sons, Ltd
Certificateless aggregate signature can provide an efficient way to verify a large amount of signatures from different users. This feature makes it very useful in the environments with low bandwidth communication, low storage, and low computability. Recently, Chen et al. proposed a new certificateless aggregate signature scheme. They claim that their scheme is provably secure under the computational Diffie-Hellman problem. Unfortunately, this paper shows that Chen et al.'s scheme is insecure, it cannot resist Type I and Type II adversaries, and the corresponding attacks are given. Furthermore, we also show their scheme exists a more powerful attack, namely, anyone can forge a certificateless signature on an arbitrary message in this attack. Finally, we discuss the reason to produce such attacks and give the corresponding suggestions to resist such attacks. Copyright © 2015 John Wiley & Sons, Ltd.