对Xu等提出的无证书签名方案和Fan的无证书代理签名方案进行了安全性分析,指出Xu的签名方案是可以普遍伪造的。而Fan的代理签名方案中,原始签名人在授权过程中泄露了自己的私钥,且该代理签名不能抵抗公钥替换攻击,即任何人(没有代理私钥)只要替换了原始签名人和代理签名人的公钥就可以伪造代理签名人的代理签名。
A certificateless signature scheme presented by Xu et al and a certificateless proxy signature scheme presented by Fan et al are cryptanalyzed.It is showd that Xu et al’s scheme is universally forgeable,and in Fan et al’s scheme,an original signer disclosed his private key when he delegates his signing ability to a proxy signer.Furthermore,Fan et al’s scheme cannot resist a public-key replacement attack.The attack shows that anyone who replaces an original signer’s public key and a proxy signer’s public key can forge valid proxy signatures on behalf of the proxy signer without knowledge of the proxy signer’s proxy private key.