Key Replacement Attack Against a Generic Construction of Certificateless Signature

Key Replacement Attack Against a Generic Construction of Certificateless Signature
复制标题

DOI:
10.1007/11780656_20
复制
发表时间:
2006-07
期刊:
--
影响因子:
--
通讯作者:
B. C. Hu;D. Wong;Zhenfeng Zhang;Xiaotie Deng
B. C. Hu;D. Wong;Zhenfeng Zhang;Xiaotie Deng
中科院分区:
其他
文献类型:
--
作者:
B. C. Hu;D. Wong;Zhenfeng Zhang;Xiaotie Deng

文献摘要

被引文献

相似文献

无证书密码术涉及密钥生成中心(KGC),其向用户发布部分密钥,并且用户还独立地生成附加的公开/秘密密钥对,使得仅知道部分密钥而不知道附加秘密密钥的KGC不能代表用户进行任何密码操作;并且替换公共/秘密密钥对但不知道部分密钥的第三方也不能作为用户进行任何密码操作。我们将这种由第三方发起的攻击称为密钥替换攻击。在ACISP 2004中,Yum和Lee在无证书密码学的框架下提出了一种通用的数字签名方案。在本文中,我们证明了他们的一般结构是不安全的密钥替换攻击。特别是,我们表明,他们的通用积木的安全要求是不够的,以支持他们的论文中所述的一些安全要求。然后,我们提出了一个修改他们的计划,并显示其安全性在一个新的和简化的安全模型。我们表明,我们的简化的定义和对抗模型不仅捕捉所有的无证书签名的独特功能,但也更通用时,与所有可比的。我们认为,模型本身具有独立的利益。
Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yum and Lee proposed a generic construction of digital signature schemes under the framework of certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest.