期刊论文详细信息
IEEE Access
Cryptanalysis of a Lightweight Certificateless Signature Scheme for IIOT Environments
Chuan Zhao1  Bo Zhang1  Chengyu Hu2  Tianqing Zhu3 
[1] School of Information Science and Engineering, University of Jinan, Jinan, China;School of Software, Shandong University, Jinan, China;School of Software, University of Technology Sydney, Ultimo, NSW, Australia;
关键词: Public key replacement attack;    known message attack;    digital signature;    certificateless;   
DOI  :  10.1109/ACCESS.2018.2883581
来源: DOAJ
【 摘 要 】

As an extremely significant cryptographic primitive, certificateless signature (CLS) schemes can provide message authentication with no use of traditional digital certificates. High efficiency and provable security without random oracle are challensges in designing a CLS scheme. Recently, Karati et al. proposed an efficient pairing-based CLS scheme with no use of map-to-point hash function and random oracle model to provide data authenticity in Industrial Internet of Things (IIoT) systems. The security proof was given under several hardness assumptions. However, we notice that both public key replacement attack and known message attack are existing in Karati et al.’s scheme. Any adversary without knowledge of signer’s private key is capable of forging valid signatures. This leads to several serious consequences. For example, anybody can sign IIoT data on behalf of IIoT data owner without being detected.

【 授权许可】

Unknown   

  文献评价指标  
  下载次数:0次 浏览次数:0次