2009Unpublished venueRequires access

Cryptoanalysis of Two Signcryption Schemes

Jianhong Zhang, Qin Geng

Open publisher page 1 citations

Abstract

Certificateless PKC and self-certified PKC are two new public key systems. They remove the necessity of certificate to ensure the authentication of the user's public key in CB-PKC and also overcome the inherent key escrow problem in IB-PKC. Recently, Zhang et.al proposed a self-certified signcryption scheme, and Wu et.al gave a certificateless signcryption scheme. However, in this paper, we analyze the security of Zhang et.al's self-certified signcryption scheme and Wu et.al certificateless signcryption scheme, and show that the two signcryption schemes are insecure though the two schemes were proven to be secure under the random oracle model. In the self-certified signcryption scheme, a malicious user can forge a signcryption on an arbitrary message m without CA's authentication. In Wu et.al's certificateless signcryption scheme, confidentiality of signcryption is not satisfied. Namely, the scheme is not against chosen ciphertext attack. Finally, we give the corresponding attack, and to overcome the above flaws, we also discuss the corresponding improved method, respectively.

About this research paper

What this paper is about

Certificateless PKC and self-certified PKC are two new public key systems. They remove the necessity of certificate to ensure the authentication of the user's public key in CB-PKC and also overcome the inherent key escrow problem in IB-PKC. Recently, Zhang et.al proposed a self-certified signcryption scheme, and Wu et.al gave a certificateless signcryption scheme. However, in this paper, we analyze the security of Zhang et.al's self-certified signcryption scheme and Wu et.al certificateless signcryption scheme, and show that the two signcryption schemes are insecure though the two schemes were proven to be secure under the random oracle model. In the self-certified signcryption scheme, a malicious user can forge a signcryption on an arbitrary message m without CA's authentication. In Wu et.al's certificateless signcryption scheme, confidentiality of signcryption is not satisfied. Namely, the scheme is not against chosen ciphertext attack. Finally, we give the corresponding attack, and to overcome the above flaws, we also discuss the corresponding improved method, respectively.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Certificateless PKC and self-certified PKC are two new public key systems. They remove the necessity of certificate to ensure the authentication of the user's public key in CB-PKC and also overcome the inherent key escrow problem in IB-PKC. Recently, Zhang et.al proposed a self-certified signcryption scheme, and Wu et.al gave a certificateless signcryption scheme. However, in this paper, we analyze the security of Zhang et.al's self-certified signcryption scheme and Wu et.al certificateless signcryption scheme, and show that the two signcryption schemes are insecure though the two schemes were proven to be secure under the random oracle model. In the self-certified signcryption scheme, a malicious user can forge a signcryption on an arbitrary message m without CA's authentication. In Wu et.al's certificateless signcryption scheme, confidentiality of signcryption is not satisfied. Namely, the scheme is not against chosen ciphertext attack. Finally, we give the corresponding attack, and to overcome the above flaws, we also discuss the corresponding improved method, respectively.

Key concepts: Signcryption, Random oracle, Public-key cryptography, Key escrow, Computer science, Authentication (law), Scheme (mathematics), Key (lock)

Related papers

Back to paper searchBrowse research topicsOriginal source
Cryptoanalysis of Two Signcryption Schemes — Research Paper | ScholarLens