对Ji—Yang签密方案进行了分析,指出一个仲裁者能利用持有的会话密钥伪造一个合法的签密,该方案不具备IND-CCA2安全性.针对Ji—Yang方案的安全缺陷,提出了一种改进的公开可验证签密方案.通过引入一个强抗碰撞哈希函数来提高加密部分和签名部分的耦合性,并对消息的哈希值进行数字签名处理,避免了仲裁者进行的存在性伪造攻击.改进方案在基本保持原方案计算和空间开销的同时,还具备强保密性、抗仲裁者攻击和公开可验证等特性.
Ji-Yang's signcryption scheme was analyzed and its flaw was pointed out. An improved publicly verifiable signcryption scheme was proposed. Being different from existing schemes, this scheme introduced a strong anti-collision hash function to enhance the coupling of encryption and signature. In addition, hashed messages were signed using digital signature technology in proposed scheme. The proposed scheme is strong existentially unforgeable under active chosen message attack and is of strong confidentiality against outer adversary and the third party. The proposed scheme is almost as efficient as the Ji-Yang's one on both computational cost and spatial cost, also has strong confidentiality, the arbiter of anti-attack and publicity verifiable characteristics.