位置:成果数据库 > 期刊 > 期刊详情页
一种改进的RSA基无证书多重签名方案
  • ISSN号:2096-3246
  • 期刊名称:《工程科学与技术》
  • 时间:0
  • 分类:TN918.1[电子电信—通信与信息系统;电子电信—信息与通信工程]
  • 作者机构:闽南师范大学计算机学院,福建漳州363000
  • 相关基金:国家自然科学基金资助项目(61170246); 福建省中青年教师教育科研基金资助项目(JA15317)
中文摘要:

针对刘莉等基于RSA的无证书多重签名方案构造了3类伪造攻击,攻击显示该方案存在公钥替换攻击的缺陷,同时该方案也无法抵抗不诚实用户或不诚实用户与恶意密钥生成中心(key generation center,KGC)的合谋攻击。分析发现原方案不安全的主要原因在于把敌手不能伪造一个有效的个体签名直接等同于敌手不能伪造一个有效的多重签名。针对目前无证书多重签名的安全模型不够严谨的现状,给出安全增强的无证书多重签名的安全模型,该模型保证多重签名是有效的,当且仅当所有个体签名都是有效的。通过在部分私钥生成阶段对用户公钥的部分参数进行签名,在多重签名阶段将个体签名与用户公钥进行绑定,将其放进Hash函数进行散列计算,给出抗合谋攻击的改进方案。改进方案无需依赖于安全信道,其签名阶段较原方案减少L个指数运算和L-3个乘法运算,验证阶段较原方案减少3个指数运算,签名长度较原方案减少|N|比特,其中L代表签名者个数,|N|代表系统参数N的比特长度,因而具有更优的运行效率。在随机预言机模型下,改进方案的个体签名在RSA和离散对数困难性假设下是可证安全的,而多重签名的不可伪造性是通过Hash函数的抗碰撞特性来保证的。

英文摘要:

Three forgery attacks on Liu Li et al.'s RSA-based certificateless multi-signature scheme were first presented.It could be found that their scheme was vulnerable to key replacement attacks.The scheme also could not resist conspiracy attack of dishonest signers or a dishonest signer with a malicious key generation center (KGC).Analysis revealed that the main reason of insecurity of the original scheme was that the for- gery of a valid individual signature was equivalent to the forgery of a valid multi-signature generated by an adversary.Sincethe existing security models of certificateless multi-signature were not so rigorous,an improved security model was developed in this paper.It guaranteed that the multi- signature was valid if and only if every individual signature was valid.By means of signing the part of the user's public key in the stage of partial private key generation,and binding the individual signature and user's public key to hash function in the stage of multi-signature generation,an improved scheme resistant to conspiracy attack was proposed.The improved scheme did not rely on secure channels and had better efficiency.The costs were reduced by L exponentiations and L-3 multiplications in the stage of multi-signature generation and three exponentiations in the stage of multi-signature verification,where L was the number of signers.The size of the signature was decreased by |N| bits,where INl was the binary length of the system parameter N.The individual signature was provably secure under assumptions of intractability of RSA and discrete logarithm.The unforgeability of multi-signature was achieved through the collision resistance property of hash function.

同期刊论文项目
期刊论文 67 会议论文 4
同项目期刊论文
期刊信息
  • 《工程科学与技术》
  • 中国科技核心期刊
  • 主管单位:中华人民共和国教育部
  • 主办单位:四川大学
  • 主编:谢和平
  • 地址:成都市一环路南一段24号
  • 邮编:610065
  • 邮箱:jsu@scu.edu.cn;jscu@163.com
  • 电话:028-85405425
  • 国际标准刊号:ISSN:2096-3246
  • 国内统一刊号:ISSN:51-1773/TB
  • 邮发代号:62-55
  • 获奖情况:
  • 国内外数据库收录:
  • 俄罗斯文摘杂志,美国化学文摘(网络版),美国数学评论(网络版),德国数学文摘,荷兰文摘与引文数据库,美国工程索引,美国剑桥科学文摘,日本日本科学技术振兴机构数据库,中国中国科技核心期刊,中国北大核心期刊(2004版),中国北大核心期刊(2008版),中国北大核心期刊(2011版),中国北大核心期刊(2014版)
  • 被引量:19