Attack on a certificateless signature and threshold proxy signature with revoking anonymity
Jianhong Zhang, Xiuna Su · 2010
Certificateless cryptography is an alternative cryptography, since it eliminates the use of certificates in traditional public key cryptography and the key-escrow problem in identity based cryptography. Proxy signature is an important delegation technique. Certificateless cryptography and proxy signature play an important role in e-commerce. Recently, Xu et.al proposed a certificateless signature for mobile wireless cyber-physical system. In the paper, we show that the scheme is insecure and give stronger attack on the scheme. And we also analyze the security of a blind threshold proxy signature scheme with revoking anonymity and show that the scheme is insecure against proxy signer's attack, namely, $m$ proxy signers can produce a forged proxy signature on arbitrary a message without original signer's delegation.