聚合签名因其在物联网中的广泛应用而成为数字签名技术研究的热点。Ming等(2014)提出了一个高效的无证书聚合签名方案,但Zhang等(2015)指出Ming方案不能抵抗类型II敌手的攻击,并给出了Ming方案的2种改进。指出Zhang等的第二个改进方案是不安全的,通过构造具体的攻击方法,证明了第二个方案无法抵抗类型II敌手的攻击。接着基于Ming方案构造了一个新的无证书聚合签名方案,在随机预言机模型下证明了新方案是安全的,且方案生成的聚合签名长度是固定的,很适合于物联网应用环境。
Aggregate signature becomes a hot topic in the digital signature technology researches because of its wide application in the Internet of Things.Ming et al.(201 4)proposed an efficient certificateless aggregate signature scheme.But Zhang et al.(201 5 )showed the scheme is not secure against a Type II adversary,and then they proposed an improvement of Ming's scheme.However,it is pointed out that the improved scheme is still insecure against a Type II adversary by giving specific attacks.Then,based on Ming's scheme,a new certificateless aggregate signature scheme is constructed.The new scheme is prov-ably-secure in the random oracle model and the length of aggregate signature is constant so that it is suit-able for the Internet of Things.