Lightweight Certificateless Signature Scheme for Resource-Constrained IoT Environment
摘要
With the widespread application of the Internet of things (IoT), the resource-constrained nature of IoT devices makes the security issues increasingly emerge. Certificateless cryptography has received significant attention due to the avoidance of complex certificate management and the removal of key escrow issues. A large number of certificateless signature schemes have been proposed; however, most of them have been shown to be insecure against public-key replacement attacks or malicious-but-passive KGC attacks. It is a challenge how to construct a secure and light certificateless signature suitable for the IoT yet. Recently, Xiang et al. proposed a lightweight certificateless signature scheme for the IoT which is claimed to be secure. However, by analyzing it, we find that it is vulnerable to public key replacement attacks. To overcome the above issue, we construct a secure and lightweight certificateless signature scheme in this work. It not only proves to be secure against two types of adversaries but also avoids time-consuming pairing. Finally, compared with recent several CLS signature schemes, evaluation results show that our scheme is comparable to the other schemes in terms of overall performance and security.