cronokirby

(2026-06) Security Analysis of One Lightweight Certificateless Mutual Authentication Scheme Based on Signatures for IIoT

2026-06-22

Abstract

We show that the certificateless signature scheme [IEEE ITJ, 26852-26865, 2024] is insecure against public key replacement attack. An adversary can forge signatures for any message by replacing the signer's public key. We find the two components δA\delta_A and TAT_A of signature σA=(mA,IDA,δA,TA)\sigma_A=(m_A, ID_A, \delta_A, T_A) are not tightly bound to the target message mAm_A and the singer's identity IDAID_A. The inherent flaw results in that the adversary can find an efficient signing algorithm functionally equivalent to the valid signing algorithm. The findings could be helpful for researchers unfamiliar with the designing techniques for certificateless signatures.