针对最近提出的两个无证书代理签名方案及其改进方案,从密码学的角度对其安全性进行了研究,指出其存在相同的安全性缺陷,即攻击者能够实施公钥替换攻击,从而能伪造出有效签名,并分析了存在公钥替换攻击的正确性及原因。同时,也指出了另外一个缺陷即攻击者可以假冒原始签名人将任何消息的代理签名权委托给任何代理人。实验结果表明,该方案的设计并不满足数字签名方案所需的安全性要求。最后,给出了克服各种攻击的改进措施。
The security of two certificateless proxy signature scheme and their improved scheme from the cryptograph point of view is studied. It is pointed out that they have the same defect in security which is the attacker can forge an effective signer to actualize an attack of public key replace. There is also the analysis of correctness and reasons of the public key replace attack given. At the same time, another defect which is the attacker can personate the origin signer to give the proxy signature of any message to any other proxy. The result shows that these schemes are not satisfy the security requires needed in digital signature scheme. In the last, the improved measures is given to overcome the various attack.