Paper 2026/1304

Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for IIoT

Zhengjun Cao
Lihua Liu
Abstract

We show that the certificateless signature scheme [IEEE ITJ, 26852-26865, 2024] is insecure against public key replacement attack. An adversary can forge signatures for any message by replacing the signer's public key. We find the two components $\delta_A$ and $T_A$ of signature $\sigma_A=(m_A, ID_A, \delta_A, T_A)$ are not tightly bound to the target message $m_A$ and the singer's identity $ID_A$. The inherent flaw results in that the adversary can find an efficient signing algorithm functionally equivalent to the valid signing algorithm. The findings could be helpful for researchers unfamiliar with the designing techniques for certificateless signatures.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Certificateless signatureforgery attacksigning algorithmverification algorithm
Contact author(s)
liulh @ shmtu edu cn
History
2026-06-24: approved
2026-06-22: received
See all versions
Short URL
https://ia.cr/2026/1304
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2026/1304,
      author = {Zhengjun Cao and Lihua Liu},
      title = {Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for {IIoT}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1304},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1304}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.