Forgery of Provable Secure Short Signcryption Scheme
C.-H. TAN · IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences · 2007
In this paper, we analyse Ma signcryption scheme [4] proposed in Inscrypt'2006. Although Ma signcryption scheme [4] is probably secure against adaptive chosen ciphertext attacks and forgery, we show that Ma signcryption scheme is easily forgeable by the receiver and the receiver can impersonate the sender to forge any valid signcryption to any receiver.