关于两类ElGamal型数字签名方案的安全性和性能分析的讨论
DISCUSSION ON SECURITY AND PERFORMANCE ANALYSIS OF TWO KINDS OF ELGAMAL SIGNATURE SCHEMES
-
摘要: 为了加强ElGamal型数字签名方案的安全性,最近祁明等人对两类ElGamal型数字签名方案的安全性和基于两类签名方案的通行字认证方案进行了分析和讨论,并且提出了两类改进型的方案。本文首先指出了他们提出的第一个p型方案是不安全的,攻击者可以伪造任意消息的数字签名。本文证明了广义ElGamal型数字签名方案都不能抵御代换攻击。本文最后还证明了他们提出的两类改进型方案也不能抵御同态攻击,因而并不具有所说的安全性。Abstract: Qi Ming and others recently analyzed and discussed the security of two kinds of the ElGamal signature schemes and the password authentication scheme based on two kinds of the signature schemes,and proposed two kinds of improved schemes.This paper first points out that the first p type signature scheme proposed by Qi is not secure,since attackers can forge signature for any message.Then this paper shows that the generalized ElGamal signature schemes can not resist the substitution attack.Finally this paper shows that two kinds of the improved schemes proposed by Qi can not resist the homomorphism attack,and does not have the security as Qi said.
-
祁明,肖国镇.两类ElGamal型数字签名方案的安全性和性能分析,电子科学学刊,1997,19(3):346-349.[2]Chang C C,Liao W Y.A remote password authentication scheme based upon ElGamals signature scheme,Computer and Security,1994,13(2):137-144.[3]Harn L,Xu Y.Design of generalized ElGamal type digital signature schemes based on the discrete logarithm,Electron.Lett.,1994,31(24):2025-2026.[4]Boyb C.New digital signature scheme based on discrete logarithm(comment),Electron.Lett.,1994,30(6):480-481.[5]Nyberg K.New digital signature scheme based on discrete logarithm(comment),Electron[J].Lett.1994,30(6):481-[6]祁明,肖国镇.加强广义ElGamal型签名方案的安全性,电子学报,1996,24(11):68-72.[7]He J,Keisler T.Enhancing the security of ElGamals signature scheme,IEE Proc[J].Comput.Digit.Tech.1994,141(4):249-252[8]Ham L.Enhancing the security of ElGamals signature scheme (comment),IEE Proc[J].Comput.Digit.Tech.1995,142(5):376-
计量
- 文章访问数: 2535
- HTML全文浏览量: 139
- PDF下载量: 438
- 被引次数: 0