摘要
对Yang等最近提出的可验证加密签名方案进行了安全性分析,结论是虽然这个方案在标准模型下是可证明安全的,但是在多用户环境下容易遭受密钥替换攻击,即一个敌手能够生成一个新公钥满足合法签名者的可验证加密签名。给出了一个具体实例,说明容易遭受密钥替换攻击的可验证加密签名如果用于公平交换协议中,在多用户环境下会违背公平交换协议的公平性。
The security of Yang et al. veriflably encrypted signature schemes is analyzed.Although the scheme is proved security in the standard model,it is vulnerable to key substitution attack in a multi-user setting,where an adversary can generate new keys satisfying legitimate verifiably encrypted signatures created by the legitimate users.A concrete instance of fair exchange of digital signature protocol is given to show that this kind attack can breach the fairness when they are used in fair exchange in a multi-user setting.
出处
《计算机工程与应用》
CSCD
北大核心
2009年第30期13-14,18,共3页
Computer Engineering and Applications
基金
国家高技术研究发展计划(863)No.2009AA012415~~
关键词
可验证加密签名
公平交换
密钥替换攻击
verifiably encrypted signature
fair exchange
key substitution attack