• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2014, Vol. 36 ›› Issue (05): 856-859.

• 论文 • 上一篇    下一篇

两个自认证签密方案的攻击及改进

王云   

  1. (青海大学成人教育学院,青海 西宁 810001)
  • 收稿日期:2012-12-24 修回日期:2013-04-10 出版日期:2014-05-25 发布日期:2013-04-10
  • 基金资助:

    国家自然科学基金资助项目(60863006)

Attacks and improvement of two
self-certified signcryption schemes

WANG  Yun   

  1. (College of Adult Education,Qinghai University,Xining 810001,China)
  • Received:2012-12-24 Revised:2013-04-10 Online:2014-05-25 Published:2013-04-10

摘要:

自认证公钥密码体制与签密思想相结合,使得消息在一个合理逻辑步骤内既签名又加密,同时无需公钥证书和密钥托管,为系统节约开销和存储空间,设计安全、高效的自认证签密方案尤为重要。通过对两个自认证签密方案的分析研究,发现这两个签密方案都是不安全的。存在已知明文与密文对的伪造攻击,任何第三方均可借助窃取到的明文与密文对假冒发送方伪造任意消息的签名。进而对第一个方案提出改进,通过添加随机数的方法,克服了原方案的安全隐患,提高了原方案的安全性能。

关键词: 自认证公钥, 自认证签密, 离散对数问题, 攻击

Abstract:

Integrating the selfcertified public key technique and signcryption system enables both digital signature and encryption simultaneously in a fitted logical procedure and eliminates the certificate management problem and the key escrow problem. It has lower computational cost and saves the storage space, so it is important for us to construct secure and efficient self certified signcryption schemes. Analysis of Yu’s and Wang’s papers shows that they are not secure.The third can forge signature instead of the true signer with a pair of clear text and cipher text. We improve their schemes by rooting a random number in the digital signature scheme.Our improvement overcomes their disadvantage and achieves a higher security.
      

Key words: self-certified public key;selfcertified signcryption;discrete logarithm problem;attack