Paper 2026/1304
Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for IIoT
Abstract
We show that the certificateless signature scheme [IEEE ITJ, 26852-26865, 2024] is insecure against public key replacement attack. An adversary can forge signatures for any message by replacing the signer's public key. We find the two components $\delta_A$ and $T_A$ of signature $\sigma_A=(m_A, ID_A, \delta_A, T_A)$ are not tightly bound to the target message $m_A$ and the singer's identity $ID_A$. The inherent flaw results in that the adversary can find an efficient signing algorithm functionally equivalent to the valid signing algorithm. The findings could be helpful for researchers unfamiliar with the designing techniques for certificateless signatures.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Certificateless signatureforgery attacksigning algorithmverification algorithm
- Contact author(s)
- liulh @ shmtu edu cn
- History
- 2026-06-24: approved
- 2026-06-22: received
- See all versions
- Short URL
- https://ia.cr/2026/1304
- License
-
CC0
BibTeX
@misc{cryptoeprint:2026/1304,
author = {Zhengjun Cao and Lihua Liu},
title = {Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for {IIoT}},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1304},
year = {2026},
url = {https://eprint.iacr.org/2026/1304}
}