ACM Home Page
Please provide us with feedback. Feedback
Malicious KGC attacks in certificateless cryptography
Full text PdfPdf (491 KB)
Source ASIAN ACM Symposium on Information, Computer and Communications Security archive
Proceedings of the 2nd ACM symposium on Information, computer and communications security table of contents
Singapore
SESSION: Cryptosystems & analysis table of contents
Pages: 302 - 311  
Year of Publication: 2007
ISBN:1-59593-574-6
Authors
Man Ho Au  University of Wollongong, Wollongong, Australia
Yi Mu  University of Wollongong, Wollongong, Australia
Jing Chen  Tsinghua University, Beijing, China
Duncan S. Wong  City University of Hong Kong, Hong Kong, China
Joseph K. Liu  University of Bristol, Bristol, UK
Guomin Yang  City University of Hong Kong, Hong Kong, China
Sponsor
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 15,   Downloads (12 Months): 111,   Citation Count: 3
Additional Information:

abstract   references   cited by   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1229285.1266997
What is a DOI?

ABSTRACT

Identity-based cryptosystems have an inherent key escrow issue, that is, the Key Generation Center (KGC) always knows user secret key. If the KGC is malicious, it can always impersonate the user. Certificateless cryptography, introduced by Al-Riyami and Paterson in 2003, is intended to solve this problem. However, in all the previously proposed certificateless schemes, it is always assumed that the malicious KGC starts launching attacks (so-called Type II attacks) only after it has generated a master public/secret key pair honestly. In this paper, we propose new security models that remove this assumption for both certificateless signature and encryption schemes. Under the new models, we show that a class of certificateless encryption and signature schemes proposed previously are insecure. These schemes still suffer from the key escrow problem. On the other side, we also give new proofs to show that there are two generic constructions, one for certificateless signature and the other for certificateless encryption, proposed recently that are secure under our new models.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
S. S. Al-Riyami and K. G. Paterson. Certificateless public key cryptography. In Proc. ASIACRYPT 2003, pages 452--473. Springer-Verlag, 2003. LNCS 2894.
 
2
S. S. Al-Riyami and K. G. Paterson. CBE from CL-PKE: A generic construction and efficient schemes. In 8th International Workshop on Theory and Practice in Public Key Cryptography (PKC 2005), pages 398--415. Springer, 2005. LNCS 3386.
 
3
J. Baek, R. Safavi-Naini, and W. Susilo. Certificateless public key encryption without pairing. In 8th Information Security Conference (ISC'05), pages 134--148. Springer, 2005. LNCS 3650.
 
4
M. Bellare, C. Namprempre, and G. Neven. Security proofs for identity-based identification and signature schemes. In Proc. EUROCRYPT 2004, pages 268--286. Springer-Verlag, 2004. LNCS 3027 (Full paper is available at Bellare's homepage URL: http://www-cse.ucsd.edu/users/mihir).
5
 
6
K. Bentahar, P. Farshim, J. Malone-Lee, and N. P. Smart. Generic construction of identity-based and certificateless KEMs. Cryptology ePrint Archive, Report 2005/058, 2005. http://eprint.iacr.org/2005/058.
 
7
 
8
 
9
Z. H. Cheng and R. Comley. Efficient certificateless public key encryption. Cryptology ePrint Archive, Report 2005/012, 2005. http://eprint.iacr.org/2005/012.
 
10
A. W. Dent. A survey of certificateless encryption schemes and security models. Cryptology ePrint Archive, Report 2006/211, 2006. http://eprint.iacr.org/2006/211.
 
11
 
12
D. Galindo, P. Morillo, and C. Ràfols. Breaking Yum and Lee generic constructions of certificate-less and certificate-based encryption schemes. In 3rd European PKI Workshop: Theory and Practice (EuroPKI 2006), pages 81--91. Springer, 2006. LNCS 4043.
 
13
 
14
B. C. Hu, D. S. Wong, Z. Zhang, and X. Deng. Key replacement attack against a generic construction of certificateless signature. In Information Security and Privacy: 11th Australasian Conference, ACISP 2006, pages 235--246. Springer-Verlag, 2006. LNCS 4058.
 
15
X. Huang, W. Susilo, Y. Mu, and F. Zhang. On the security of certificateless signature schemes from Asiacrypt 2003. In Cryptology and Network Security, 4th International Conference, CANS 2005, pages 13--25. Springer-Verlag, 2005. LNCS 3810.
 
16
X. Li, K. Chen, and L. Sun. Certificateless signature and proxy signature schemes from bilinear pairings. Lithuanian Mathematical Journal, 45(1):76--83, 2005.
 
17
B. Libert and J.-J. Quisquater. On constructing certificateless cryptosystems from identity based encryption. In 9th International Conference on Theory and Practice in Public Key Cryptography (PKC 2006), pages 474--490. Springer, 2006. LNCS 3958.
 
18
 
19
D. H. Yum and P. J. Lee. Generic construction of certificateless encryption. In ICCSA '04, pages 802--811. Springer, 2004. LNCS 3043.
 
20
D. H. Yum and P. J. Lee. Generic construction of certificateless signature. In Information Security and Privacy: 9th Australasian Conference, ACISP 2004, pages 200--211. Springer-Verlag, 2004. LNCS 3108.
 
21
D. H. Yum and P. J. Lee. Identity-based cryptography in public key management. In EuroPKI'04, pages 71--84. Springer, 2004. LNCS 3093.
 
22
Z. Zhang, D. Wong, J. Xu, and D. Feng. Certificateless public-key signature: Security model and efficient construction. In 4th International Conference on Applied Cryptography and Network Security (ACNS 2006), pages 293--308. Springer, 2006. LNCS 3989.

Collaborative Colleagues:
Man Ho Au: colleagues
Yi Mu: colleagues
Jing Chen: colleagues
Duncan S. Wong: colleagues
Joseph K. Liu: colleagues
Guomin Yang: colleagues