On the Security of a Group Signcryption Scheme from Distributed Signcryption Scheme
2005; Springer Science+Business Media; Linguagem: Inglês
10.1007/11599371_3
ISSN1611-3349
AutoresHaiyong Bao, Zhenfu Cao, Haifeng Qian,
Tópico(s)Cryptography and Residue Arithmetic
ResumoSigncryption denotes a cryptographic method, which can process encryption and digital signature simultaneously. So, adopting such schemes, computational cost of encryption and signature compared to traditional signature-then-encryption can be reduced to a great extent. Based on the existing distributed signcryption schemes, Kwak and Moon proposed a new distributed signcryption scheme with sender ID confidentiality and extended it to a group signcryption. Their scheme is more efficient in both communication and computation aspects. Unfortunately we will demonstrate that their scheme is insecure by identifying some security flaws. Exploring these flaws, an attacker without any secret can mount universal forging attacks. That is, anyone (not necessary the group member) can forge valid group signatures on arbitrary messages of his/her choice.
Referência(s)