Title :
Cryptoanalysis of Two Signcryption Schemes
Author :
Zhang, Jianhong ; Geng, Qin
Author_Institution :
Coll. of Sci., North China Univ. of Technol., Beijing, China
Abstract :
Certificateless PKC and self-certified PKC are two new public key systems. They remove the necessity of certificate to ensure the authentication of the user´s public key in CB-PKC and also overcome the inherent key escrow problem in IB-PKC. Recently, Zhang et.al proposed a self-certified signcryption scheme, and Wu et.al gave a certificateless signcryption scheme. However, in this paper, we analyze the security of Zhang et.al´s self-certified signcryption scheme and Wu et.al certificateless signcryption scheme, and show that the two signcryption schemes are insecure though the two schemes were proven to be secure under the random oracle model. In the self-certified signcryption scheme, a malicious user can forge a signcryption on an arbitrary message m without CA´s authentication. In Wu et.al´s certificateless signcryption scheme, confidentiality of signcryption is not satisfied. Namely, the scheme is not against chosen ciphertext attack. Finally, we give the corresponding attack, and to overcome the above flaws, we also discuss the corresponding improved method, respectively.
Keywords :
public key cryptography; authentication; certificateless public key cryptography; ciphertext attack; cryptoanalysis; self-certified signcryption; Authentication; Certification; Computational efficiency; Digital signatures; Educational institutions; Information security; Logic; Public key; Public key cryptography; attack; certificateless signcryption; self-certified signcryption;
Conference_Titel :
Information Assurance and Security, 2009. IAS '09. Fifth International Conference on
Conference_Location :
Xian
Print_ISBN :
978-0-7695-3744-3
DOI :
10.1109/IAS.2009.101