论文部分内容阅读
无证书公钥密码体制消除了PKI(公钥基础设施)中的证书,同时解决了基于身份的公钥密码体制中的密钥托管问题。文中对文献[9]提出的无证书代理签名方案进行了安全性分析,通过分析表明该方案对于无证书密码体制中两种类型的攻击即公钥替换攻击和恶意KGC(Key Generating Centre)攻击都是不安全的。从而针对公钥替换攻击和恶意KGC攻击提出了一个改进方案,通过分析改进方案满足代理签名的安全性要求,能有效抵抗公钥替换攻击和恶意KGC攻击。
The certificateless public key cryptosystem eliminates certificates in PKI (Public Key Infrastructure) and solves the key escrow problem in identity-based public-key cryptography. The paper analyzes the security of the certificateless proxy signature scheme proposed in [9]. The analysis shows that the proposed scheme is effective against both types of attacks in the certificateless cryptosystem, that is, public key replacement attack and KGC (Key Generating Center) attacks It is unsafe. Therefore, aiming at the public key replacement attacks and malicious KGC attacks, an improved scheme is proposed. By analyzing the improved scheme to meet the security requirements of proxy signature, it can effectively resist the public key replacement attacks and malicious KGC attacks.