On The Security of Two Key-Updating Signature Schemes

Guo Xing-yang · IACR Cryptology ePrint Archive · 2004

In ICICS 2004, Gonzalez-Deleito, Markowitch and Dall'Olio proposed an efficient strong key-insulated signature scheme. They claimed that it is (N�1,N)-key-insulated, i.e., the compromise of the secret keys for arbitrarily many time periods does not expose the secret keys for any of the remaining time periods. But in this paper, we demonstrate an at- tack and show that an adversary armed with the signing keys for any two time periods can compute the signing keys for the remaining time peri- ods except for some very special cases. In a second attack, the adversary can forge signatures for many remaining time periods without comput- ing the corresponding signing keys. Therefore it is only equivalent to a (1,N)-key-insulated signature scheme. A variant forward-secure signa- ture scheme was also presented in ICICS 2004 and claimed more robust than traditional forward-secure signature schemes. But we find that the scheme has two similar weaknesses. We try to repair the two schemes in this paper.

Read the paper · More papers on PaperTik