引用本文:禹勇,倪剑兵,许春香,牛磊.安全高效基于身份签名方案的密码学分析.软件学报,2014,25(5):1125-1131
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 4460次   下载 6839 本文二维码信息
码上扫一扫!
分享到: 微信 更多
安全高效基于身份签名方案的密码学分析
禹勇1,2, 倪剑兵1, 许春香1, 牛磊1
1.电子科技大学 计算机科学与工程学院, 四川 成都 611731;2.School of Computer Science and Software Engineering, University of Wollongong, Australia
摘要:
基于身份的数字签名方案最显著的特点是,只需要签名人的身份信息而无需签名人的证书来验证签名的有效性,这极大地简化了密钥管理.2006年,Paterson和Schuldt构造了标准模型下可证明安全的基于身份的数字签名方案,但计算效率不高.谷科等人提出了新型的改进方案来提高效率,并声称新方案在标准模型下可证明安全且比同类方案更高效.然而,新方案并不具备不可伪造性.给出了两种具体的攻击:敌手可以伪造用户的密钥或者敌手可以直接伪造任何消息的签名.进一步指出安全性证明中的缺陷,即,敌手的view与安全模拟成功的事件不独立.
关键词:  数字签名  基于身份签名  标准模型  密码学分析  可证明安全
DOI:10.13328/j.cnki.jos.004526
分类号:
基金项目:国家自然科学基金(61003232,61370203,61250110543);教育部博士点基金(20100185120012)
Cryptanalysis of a Secure and Efficient Identity-Based Signature Scheme
YU Yong1,2, NI Jian-Bing1, XU Chun-Xiang1, NIU Lei1
1.School of Computer Science and Engineering, University of Electronics Science and Technology of China, Chengdu 611731, China;2.School of Computer Science and Software Engineering, University of Wollongong, Australia
Abstract:
The distinguishing characteristic of identity-based signatures is that only the identity with no certificate of a signer is involved in the verification of a signature, which simplifies the key management procedures dramatically. A novel identity-based signature scheme that can be proven secure in the standard model was given by Paterson and Schuldt in 2006. Unfortunately, the scheme is not efficient in computation. An improvement due to Gu, et al. was proposed recently to improve the computational efficiency, and it was claimed as being provably secure in the standard model and more efficient than the known schemes in the same flavor. However, this paper shows that the new scheme by Gu, et al. is insecure by demonstrating two concrete attacks in which an adversary can not only forge the private key of an identity but also forge signatures on arbitrary message. The study also identifies a flaw in their security proofs, i.e., the view of the adversary in the security reduction is not independent of the event that the simulation succeeds.
Key words:  digital signature  identity-based signature  standard model  cryptanalysis  provable security

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: