首页> 外文会议>Australasian Conference on Information Security and Privacy >Key Replacement Attack Against a Generic Construction of Certificateless Signature
【24h】

Key Replacement Attack Against a Generic Construction of Certificateless Signature

机译:密钥替代攻击对无证书签名的通用构建

获取原文

摘要

Certificateless cryptography involves a Key Generation Center (KGC) which issues a partial key to a user and the user also independently generates an additional public/secret key pair in such a way that the KGC who knows only the partial key but not the additional secret key is not able to do any cryptographic operation on behalf of the user; and a third party who replaces the public/secret key pair but does not know the partial key cannot do any cryptographic operation as the user either. We call this attack launched by the third party as the key replacement attack. In ACISP 2004, Yum and Lee proposed a generic construction of digital signature schemes under the framework of certificateless cryptography. In this paper, we show that their generic construction is insecure against key replacement attack. In particular, we show that the security requirements of their generic building blocks are insufficient to support some security claim stated in their paper. We then propose a modification of their scheme and show its security in a new and simplified security model. We show that our simplified definition and adversarial model not only capture all the distinct features of certificateless signature but are also more versatile when compared with all the comparable ones. We believe that the model itself is of independent interest.
机译:证书密码涉及密钥生成中心(KGC),它发出的部分关键,用户和用户也分别以这样的方式产生额外的公共/私钥对,谁知道只有部分关键,但没有额外的秘密密钥的KGC不能做代表用户的任何加密操作;与第三方谁取代了公/私钥对,但不知道部分密钥不能做任何加密操作,用户要么。我们称这种攻击由第三方发起的密钥替换攻击。 2004年ACISP,百胜和Lee提出的数字签名方案的通用结构证书密码的框架下。在本文中,我们证明了自己的通用结构是针对重点攻击的更换不安全。特别是,我们证明了自己的通用构建模块的安全需求不足以支持他们的文件中指出了一些安全要求。然后,我们提出了自己的方案的修改,显示其安全性在一个新的和简化的安全模型。我们证明了我们的简化定义和对抗模式不仅能够捕捉证书签名的所有不同的功能,但也当所有可比那些相比,更灵活。我们认为,该模型本身是独立的利益的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号