TY - GEN
T1 - Key replacement attack against a generic construction of certificateless signature
AU - Hu, Bessie C.
AU - Wong, Duncan S.
AU - Zhang, Zhenfeng
AU - Deng, Xiaotie
PY - 2006
Y1 - 2006
N2 - Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yutn and Lee proposed a generic construction of digital signature schemes under the framework of certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest. © Springer-Verlag Berlin Heidelberg 2006.
AB - Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yutn and Lee proposed a generic construction of digital signature schemes under the framework of certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest. © Springer-Verlag Berlin Heidelberg 2006.
UR - https://www.scopus.com/pages/publications/33746370456
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-33746370456&origin=recordpage
U2 - 10.1007/11780656_20
DO - 10.1007/11780656_20
M3 - RGC 32 - Refereed conference paper (with host publication)
SN - 9783540354581
T3 - Lecture Notes in Computer Science
SP - 235
EP - 246
BT - Information Security and Privacy
A2 - Batten, Lynn Margaret
A2 - Safavi-Naini, Reihaneh
PB - Springer
CY - Berlin, Heidelberg
T2 - 11th Australasian Conference on Information Security and Privacy (ACISP 2006)
Y2 - 3 July 2006 through 5 July 2006
ER -