<p>In smart transportation systems, the traffic control center efficiently disseminates substantial traffic information to numerous vehicles using broadcast communication. While this method is convenient, it also brings several privacy and security challenges. Ensuring secure communication requires meeting essential security properties, including existential unforgeability of chosen message attacks (<Emphasis FontCategory="SansSerif">EUF-CMA</Emphasis>) and indistinguishability under chosen ciphertext attacks (<Emphasis FontCategory="SansSerif">IND-CCA</Emphasis>). In this paper, we analyze one of the most efficient certificateless broadcast signcryption schemes with an equality test for smart transportation systems, proposed by Niu et al. [Vehicular Communications, 2024]. Our investigation reveals that their scheme fails to meet the essential <Emphasis FontCategory="SansSerif">EUF-CMA</Emphasis> and <Emphasis FontCategory="SansSerif">IND-CCA</Emphasis> security requirements. Specifically, we show that a <Emphasis FontCategory="SansSerif">Type-I</Emphasis> adversary can forge a valid signcrypted ciphertext without access to the sender’s complete private key and can unsigncrypt ciphertexts by substituting the receiver’s public key. Moreover, our theoretical and implemental analysis reveals that these attacks incur minimal computational overhead. To mitigate these vulnerabilities, we propose two modification approaches to enhance the security of the certificateless broadcast signcryption in smart transportation systems.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

On the security of broadcast signcryption scheme with equality test in smart transportation system

  • Ramprasad Sarkar

摘要

In smart transportation systems, the traffic control center efficiently disseminates substantial traffic information to numerous vehicles using broadcast communication. While this method is convenient, it also brings several privacy and security challenges. Ensuring secure communication requires meeting essential security properties, including existential unforgeability of chosen message attacks (EUF-CMA) and indistinguishability under chosen ciphertext attacks (IND-CCA). In this paper, we analyze one of the most efficient certificateless broadcast signcryption schemes with an equality test for smart transportation systems, proposed by Niu et al. [Vehicular Communications, 2024]. Our investigation reveals that their scheme fails to meet the essential EUF-CMA and IND-CCA security requirements. Specifically, we show that a Type-I adversary can forge a valid signcrypted ciphertext without access to the sender’s complete private key and can unsigncrypt ciphertexts by substituting the receiver’s public key. Moreover, our theoretical and implemental analysis reveals that these attacks incur minimal computational overhead. To mitigate these vulnerabilities, we propose two modification approaches to enhance the security of the certificateless broadcast signcryption in smart transportation systems.