Security Analysis of a Threshold Proxy Signature Scheme Using Self-certified Public Keys
Changji Wang
Abstract
Changji Wang
Abstract
Xue and Cao proposed a threshold proxy signature scheme using self-certified public keys,but this scheme was insecure.An attack against this scheme was proposed.By this attack,an adversary could forge an illegal proxy signature.That is,based on the proxy signature generated by proxy signers on a message on behalf of an original signer,an attacker could forge a valid threshold proxy signature on the same message which seemed generated by these proxy signers on behalf of this attacker himself.After producing a forged proxy signature,the adversary had the same authority with the original signer to the proxy signer,and the verifier could not distinguish which one was the real original signer.Especially,this attack was used to change proxy signatures into threshold signatures belonging to the group that actually generated the proxy signatures.The causes of the security deficiencies existing in this scheme were analyzed and an improvement which could resolve these security deficiencies was further proposed.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Xue and Cao proposed a threshold proxy signature scheme using self-certified public keys,but this scheme was insecure.An attack against this scheme was proposed.By this attack,an adversary could forge an illegal proxy signature.That is,based on the proxy signature generated by proxy signers on a message on behalf of an original signer,an attacker could forge a valid threshold proxy signature on the same message which seemed generated by these proxy signers on behalf of this attacker himself.After producing a forged proxy signature,the adversary had the same authority with the original signer to the proxy signer,and the verifier could not distinguish which one was the real original signer.Especially,this attack was used to change proxy signatures into threshold signatures belonging to the group that actually generated the proxy signatures.The causes of the security deficiencies existing in this scheme were analyzed and an improvement which could resolve these security deficiencies was further proposed.
Key concepts: Proxy (statistics), Computer security, Adversary, Computer science, Digital signature, Cryptography, Security analysis, Hash function