对于S-H.Seo等提出的无证书代理签名方案进行了密码分析,给出了一个有效的伪造攻击算法,指出此方案不能抵抗第二种类型敌手的攻击,敌手Ⅱ可以伪造任意消息的合法代理签名。最后分析了此方案遭受攻击的主要原因,并给出了相应的改进措施。
Recently, S-H. Seo et al proposed a certificateless signature scheme and used it to construct a certificateless proxy signature with provable security. They demonstrated that their schemes are provable security in the random oracle model under the computational Diffie-Hellman assumption. Unfortunately, by given concrete attack, the paper demonstrated that their schemes were not secure against the Type Ⅱ adversary. A Type Ⅱ adversary could forge a legal proxy signature of any message. The paper analyzed the root cause of attack and gave some suggestions for modifications in the end.