对一种代理签名方案的攻击和改进

Attack and Improvement of a Proxy Signature Scheme

  • 摘要: 分析了文献12提出的一系列代理签名方案的安全性,包括基本的代理签名方案、电子支票的可控授权协议和前向安全的代理签名方案,指出这些方案是不安全的。利用伪造攻击,一个敌手可以成功伪造代理签名密钥,冒充诚实的代理签名人生成有效的代理签名,威胁原始签名人和代理签名人的合法权益,相应地,给出了修正方法抵抗代理签名密钥伪造攻击。

     

    Abstract: The security of some proxy signature schemes including a simple proxy signature scheme, controlled delegation in e-checks using proxy signature and a forward secure proxy signature scheme due to Ref.12 is analyzed. It is shown that all the schemes are insecure. A forgery attack on these schemes is proposed in this paper. Using the forgery attack, a malicious adversary can forgery a valid proxy signing key on behalf of the original signer without his/her agreement and produce valid proxy signatures, which does harm to the benefits of the original signer and the proxy signer. The corresponding corrected algorithms are proposed to resist this kind of forgery attack.

     

/

返回文章
返回