对一个改进指定验证者的代理签名方案进行了分析,指出了其中的安全漏洞.系统中的一个用户如果截取到原始签名人发送给代理签名人的信息,则可以伪造对消息的代理签名.该攻击方案可以成功的原因是在原签名方案的验证中仅使用了指定验证者的公私钥,没有其他的公钥信息.该攻击方案虽然短小,但对原始签名方案是有效的.
An improved designated verifier proxy signature scheme is analysed and a security loophole is proposed. If any user in the system intercepts the authorization information which is sent to the proxy signer from the orininal signer, he can forge a valid signature for others message. There is no any other public information, besides the desinated verifier's private key in ver fication step, which is the reason why there exists such a forgery attack. Although that forgery attack is small , it is valid to the signature scheme.