On the security of two signature schemes for secure communication in IoT environments

被引:0
|
作者
Xu, Feihong [1 ]
Zeng, Hui [2 ]
机构
[1] Wuchang Univ Technol, Sch Artificial Intelligence, Wuhan, Peoples R China
[2] Hubei Open Univ, Sch Software Engn, Wuhan, Peoples R China
关键词
Pairing; Certificateless signature; Aggregate signature; IoT; CERTIFICATELESS AGGREGATE SIGNATURE; EFFICIENT;
D O I
10.1007/s11042-023-17312-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Thumbur et al. (IEEE Commun Lett 24(8): 1641-1645, 2020) proposed a pairing-free certificateless signature (PF-CLS) scheme for secure communication in resource-constrained devices. Zhan et al. (IEEE Internet of Things Journal, pp 1-1, 2020) proposed a pairing-free certificateless aggregate signature (PF-CLAS) in healthcare wireless medical sensor networks. The authors proved the security of their schemes under the hardness of mathematical problems in the random oracle model respectively. Unfortunately, we find that the above two recent schemes are insecure. By providing concrete attacks, in this work, we show that an attacker with replacing public key ability can easily impersonate other legitimate users to upload some false messages by forging the target users' valid signatures on these messages. As a result, the above two signature schemes PF-CLS and PF-CLAS cannot solve the IoT data authenticity and integrity issues pointed out by them. Moreover, we discuss the reasons for our attacks and provide relevant improvements.
引用
收藏
页码:43673 / 43683
页数:11
相关论文
共 50 条
  • [1] On the security of two signature schemes for secure communication in IoT environments
    Feihong Xu
    Hui Zeng
    [J]. Multimedia Tools and Applications, 2024, 83 : 43673 - 43683
  • [2] Design Principles of Secure Certificateless Signature and Aggregate Signature Schemes for IoT Environments
    Shim, Kyung-Ah
    [J]. IEEE ACCESS, 2022, 10 : 124848 - 124857
  • [3] Security notions for unconditionally secure signature schemes
    Shikata, J
    Hanaoka, G
    Zheng, YL
    Imai, H
    [J]. ADVANCES IN CRYPTOLOGY - EUROCRYPT 2002, PROCEEDINGS, 2002, 2332 : 434 - 449
  • [4] On the security of two signature schemes
    Zhang, Jianhong
    Zou, Jiancheng
    [J]. 2006 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-4, 2006, : 1190 - 1193
  • [5] A Survey on Secure Group Communication Schemes With Focus on IoT Communication
    Prantl, Thomas
    Zeck, Timo
    Bauer, Andre
    Ten, Peter
    Prantl, Dominik
    Ben Yahya, Ala Eddine
    Ifflaender, Lukas
    Dmitrienko, Alexandra
    Krupitzer, Christian
    Kounev, Samuel
    [J]. IEEE ACCESS, 2022, 10 : 99944 - 99962
  • [6] Secure and lightweight communication in heterogeneous IoT environments
    Siddiqui, Farhan
    Beley, Jake
    Zeadally, Sherali
    Braught, Grant
    [J]. INTERNET OF THINGS, 2021, 14
  • [7] Security Analysis of Two Forward-Secure Threshold Signature Schemes from ICCIS
    Wang, Hong
    Qiu, Gang
    Wei, Shimin
    Zuo, Zepeng
    [J]. 2011 AASRI CONFERENCE ON APPLIED INFORMATION TECHNOLOGY (AASRI-AIT 2011), VOL 2, 2011, : 174 - 177
  • [8] Benchmarking of Secure Group Communication schemes with focus on IoT
    Thomas Prantl
    André Bauer
    Simon Engel
    Lukas Horn
    Christian Krupitzer
    Lukas Iffländer
    Samuel Kounev
    [J]. Discover Data, 2 (1):
  • [9] Security analysis of two signature schemes and their improved schemes
    Zhang, Jianhong
    Mao, Jane
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2007, PT 1, PROCEEDINGS, 2007, 4705 : 589 - +
  • [10] On the security of two group signature schemes with forward security
    Kim, Kitae
    Yie, Ikkwon
    Nyang, Daehun
    [J]. Informatica (Ljubljana), 2010, 34 (02) : 237 - 242