首页> 外文会议>Australasian Conference on Information Security and Privacy(ACISP 2006); 20060703-05; Melbourne(AU) >Key Replacement Attack Against a Generic Construction of Certificateless Signature
【24h】

Key Replacement Attack Against a Generic Construction of Certificateless Signature

机译:针对无证书签名的通用构造的密钥替换攻击

获取原文
获取原文并翻译 | 示例

摘要

Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yum and Lee proposed a generic construction of digital signature schemes under the framework of Certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of Certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest.
机译:无证书加密涉及一个密钥生成中心(KGC),该中心向用户颁发部分密钥,并且用户还以这种方式独立生成一个附加的公共/秘密密钥对,即仅知道部分密钥但不知道附加秘密密钥的KGC无法代表用户执行任何加密操作;替换公钥/秘密密钥对但不知道部分密钥的第三方也无法以用户身份进行任何加密操作。我们将这种由第三方发起的攻击称为密钥替换攻击。在ACISP 2004中,Yum和Lee在无证书密码学的框架下提出了一种数字签名方案的通用构造。在本文中,我们证明了它们的通用构造对于密钥替换攻击是不安全的。特别是,我们显示出其通用构件块的安全性要求不足以支持其论文中所述的某些安全性要求。然后,我们提出对其方案的修改,并在新的简化安全模型中显示其安全性。我们表明,我们的简化定义和对抗模型不仅捕获了无证书签名的所有独特功能,而且与所有可比功能相比,还具有更多的通用性。我们认为该模型本身具有独立利益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号