Cryptanalysis of a Certificateless Multi-receiver Signcryption Scheme

Songqin Miao, Futai Zhang, Lei Zhang · 2010

Certificateless public key cryptography eliminates certificate management in traditional public key infrastructure and solves the key escrow problem in identity-based cryptography. Certificateless signcryption is one of the most important primitives in certificateless public key cryptography which achieves confidentiality and authentication simultaneously. Multi-receiver signcryption signcrypts a message to a large number of receivers. Selvi et al. proposed the first efficient and provably secure certificateless multi-receiver signcryption scheme. Recently, they found the scheme is insecure against the type I adversary and gave an enhanced one. However, we find that their enhanced scheme is still insecure against the type I adversary. In this paper, we present an attack on Selvi et al.'s enhanced scheme. Specifically, we show that a type I adversary can first replace a sender's public key and generate a signcrypted message on behalf of the sender.

Read the paper · More papers on PaperTik