对周敏等人提出的无证书签密方案进行了安全性分析,指出该方案存在以下安全缺陷:方案不能抵抗不可区分性选择明文攻击;利用公钥替换攻击,敌手可以伪造用户对任意消息的签密;恶意KGC可以对任意消息伪造签密,也可以对任意签密文进行解密;对消息的加解密密钥不含随机因子,使得方案不具有前向安全性.
Cryptanalysis of the certificateless verifiable signcryption scheme proposed by Zhou Min et al shows that the scheme has the following security flaws: the scheme can’t resist indistinguishability under the chosen ciphertext attack;the adversary can forge a valid signcryption ciphertext for any message of any user under public key replacement attacks;the malicious KGC can forge the ciphertext for any message and can also decrypt any ciphertext;the scheme is not forward-secure because the encryption key does not contain a random number.