International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 04 April 2025

Zhengjun Cao, Lihua Liu
ePrint Report ePrint Report
We show that the attribute-based signature scheme [Information Sciences, 654(2024), 119839] is insecure, because an adversary can generate valid signatures for any message even though he cannot access the signer's secret key. The four components of signature $\{\delta_1, \delta_2, \delta_3, \delta_4\}$ are not tightly bound to the target message $M$ and the signer's public key. The dependency between the signer's public key and secret key is not properly used to construct any intractable problem. The inherent flaw results in that the adversary can find an efficient signing algorithm functionally equivalent to the valid signing algorithm.
Expand

Additional news items may be found on the IACR news page.