Skip to main navigation Skip to search Skip to main content

Key replacement attack against a generic construction of certificateless signature

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yutn and Lee proposed a generic construction of digital signature schemes under the framework of certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest. © Springer-Verlag Berlin Heidelberg 2006.
Original languageEnglish
Title of host publicationInformation Security and Privacy
Subtitle of host publication11th Australasian Conference, ACISP 2006, Melbourne, Australia, July 3-5, 2006, Proceedings
EditorsLynn Margaret Batten, Reihaneh Safavi-Naini
Place of PublicationBerlin, Heidelberg
PublisherSpringer 
Pages235-246
ISBN (Electronic)978-3-540-35459-8
ISBN (Print)9783540354581
DOIs
Publication statusPublished - 2006
Event11th Australasian Conference on Information Security and Privacy (ACISP 2006) - Melbourne, Australia
Duration: 3 Jul 20065 Jul 2006

Publication series

NameLecture Notes in Computer Science
Volume4058
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference11th Australasian Conference on Information Security and Privacy (ACISP 2006)
PlaceAustralia
CityMelbourne
Period3/07/065/07/06

Fingerprint

Dive into the research topics of 'Key replacement attack against a generic construction of certificateless signature'. Together they form a unique fingerprint.

Cite this