为了保护用户的隐私又可以避免犯罪,张等人利用基于身份的密码系统,构造了一次性公钥系统。然而,该系统是不安全的,任何人均可以利用用户的公钥信息来生成对消息的签名并将它强加给该用户。该签名一定能通过验证,当出现争议时,可信中心无法揭示签名人的真正身份。为了避免这一安全缺陷,提出了改进办法。分析表明,改进的系统克服了原系统的不足,提高了系统执行效率。
To protect individual and prevent from the consumer committing, Zhang and his partners proposed one-off public key using identity-based cryptography from bilinear pairings. However, this system was insecure, anyone could forge a signature and impose it on a legal user, and TC could not reveal the signer' s identity when in dispute. To thwart this attack, an improvement was further proposed, which could resolve the security problem existing in Zhang and his partners' schemeand could improve the efficiency in the process of executing