On the Security of Online/Offline Signatures and Multisignatures from ACISP'06

On the Security of Online/Offline Signatures and Multisignatures from ACISP'06
复制标题

DOI:
10.1007/978-3-540-89641-8_8
复制
发表时间:
2008-12
期刊:
--
影响因子:
--
通讯作者:
Fagen Li;Masaaki Shirase;T. Takagi
Fagen Li;Masaaki Shirase;T. Takagi
中科院分区:
其他
文献类型:
--
作者:
Fagen Li;Masaaki Shirase;T. Takagi

文献摘要

被引文献

相似文献

路由协议中的有效认证是自组织网络安全最重要的问题之一。在ACISP’06中,Xu、Mu和Susilo提出了一种基于身份的在线/离线签名方案,用于AODV协议中的认证,并将该方案转化为适用于DSR协议的基于身份的多重签名方案。在本文中,我们通过演示伪造攻击表明他们的方案无法实现所声称的安全性。在这种攻击中,对手可以在任何消息上伪造有效签名。因此,他们的签名方案无法保证AODV和DSR协议的安全性。我们还表明,他们从基于身份的在线/离线签名构建基于身份的多重签名是不安全的。
Efficient authentication in routing protocols is one of the most important problems for security of ad hoc networks. In ACISP’06, Xu, Mu, and Susilo proposed an identity-based online/offline signature scheme for authentication in the AODV protocol and then transformed this scheme to an identity-based multisignature scheme which is suitable for the DSR protocol. In this paper, we show that their schemes cannot achieve the claimed security by demonstrating a forgery attack. In this attack, an adversary can forge a valid signature on any messages. Therefore, their signature schemes cannot guarantee the security of AODV and DSR protocols. We also show that their generic construction of identity-based multisignature from identity-based online/offline signature is not secure.