In the circle of cloud-based Internet of Things (IoT), ensuring robust authentication and confidentiality is crucial, typically achieved through certificate-based signcryption (CBSC) schemes. These schemes combine encryption and signature functionalities to provide confidentiality, integrity, and authentication in a single logical operation. Previously, Zhou et al. (Theor Comput Sci 860:1–22, 2021) put forward a continuous leakage-resilient CBSC scheme to mitigate key exposure risks associated with the repeated use of the same private key. However, this paper presents a comprehensive analysis revealing a significant vulnerability in their CBSC scheme. Specifically, the scheme is discovered to be susceptible to attacks from a Type I (malicious user) adversary, who can exploit this vulnerability to compromise the master secret key. Such an attack can have severe repercussions, undermining the intended security and anonymity of the scheme.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cryptanalysis of Continuous Leakage-Resilient Signcryption Scheme in Cloud Computing

  • Nahida Majeed Wani,
  • Girraj Kumar Verma

摘要

In the circle of cloud-based Internet of Things (IoT), ensuring robust authentication and confidentiality is crucial, typically achieved through certificate-based signcryption (CBSC) schemes. These schemes combine encryption and signature functionalities to provide confidentiality, integrity, and authentication in a single logical operation. Previously, Zhou et al. (Theor Comput Sci 860:1–22, 2021) put forward a continuous leakage-resilient CBSC scheme to mitigate key exposure risks associated with the repeated use of the same private key. However, this paper presents a comprehensive analysis revealing a significant vulnerability in their CBSC scheme. Specifically, the scheme is discovered to be susceptible to attacks from a Type I (malicious user) adversary, who can exploit this vulnerability to compromise the master secret key. Such an attack can have severe repercussions, undermining the intended security and anonymity of the scheme.