Security analysis of Chang et al.'s signature scheme with message recovery
Xiao Guo-zhen · Journal of Xidian University · 2005
Recently,C.C.Chang and Y.F.Chang have proposed a new digital signature scheme with message recovery.Neither one-way hash functions nor message redundancy schemes are used in their scheme in order to reduce the computational cost.However,it is found that their signature scheme is not as secure as they clamied,in fact.In this paper,two kinds of forgery attacks are proposed to show that an attacker can forge valid signatures on any uncontrolled messages.To overcome these attacks,the one-way hash functions and the message redundancy schemes may still be used.