An Attack on a Certificateless Signature Scheme and Its Improvement
Xuefei Cao, Weidong Kou · Beijing Youdian Xueyuan xuebao · 2008
That a presented proposal of efficient certificateless signature scheme is insecure against public key replacement attack is demonstrated.It is shown that an adversary who replaces the public key of a signer can forge valid signatures for the signer without knowledge of the signer's private key.Then the scheme is improved by replacing the original public key with a public key pair.It enables a verifier to check the validity of a signer's public key pair by simplifying the signature construction.The improved scheme is proven secure against existential forgery under the random oracle model.