对两个无证书部分盲签名方案进行了分析,指出这两个方案都是不安全的。对于第一个方案,类型Ⅱ敌手即恶意私钥生成中心KGC可以利用在系统参数生成阶段生成的含有陷门信息的系统参数计算出目标用户的密钥,从而冒充该用户伪造签名;对于第二个方案,类型Ⅰ敌手通过替换用户的公钥伪造该用户的签名。
This paper analyzed two certificateless partially blind signature schemes.It indicated that the two certificateless partially blind signature schemes were insecure.For the one scheme,a type Ⅱ adversary,i.e.malicious private key generator(KGC),can generate the trapdoor system parameters using the identity of a chosen potential user in the Setup phase and forge a signature of the user on any message in the Signing phase.For the other scheme,a type I adversary can forge a signature of any user on any message by substituting the user's public key.