A New Efficient and Provably Secure Certificateless Signature Scheme Without Bilinear Pairings for the Internet of Things
Abstract
Highlights
- A new attack method, the Common Factor Substitution Attack, is introduced, showing that a broad class of existing pairing-free certificateless signature (PF-CLS) schemes share a common vulnerability and cannot resist Type I adversary forgeries—even after certain prior improvements.
- A new PF-CLS scheme is proposed that securely binds both parts of a user’s public key to the system public key via a hash function, eliminating the Type II attack vulnerability in Ma et al.’s scheme, and is proven secure against both Type I and Type II adversaries under the Random Oracle Model while offering higher computational efficiency than comparable schemes.
- The results underscore that many PF-CLS schemes in current use for resource-constrained environments like IoT remain insecure against forged signature attacks unless both Type I and Type II threats are systematically addressed in their design.
- The proposed scheme’s combined security and efficiency make it a strong candidate for real-world IoT deployments, improving trust in data integrity and identity authentication without imposing heavy computational or communication costs.
Abstract
1. Introduction
1.1. Related Work
1.2. Our Contributions
2. Preliminaries
2.1. Complexity Assumption
2.2. Security Model
3. Review of Four PF-CLS Schemes
3.1. Xiang et al.’s Scheme
3.2. Du et al.’s Scheme
3.3. Karati et al.’s Scheme
3.4. Pakniat and Vanda’s Scheme
4. Novel Attacks on Four Schemes
4.1. Cryptanalysis of Xiang et al.’s and Du et al.’s Schemes
4.2. Cryptanalysis of Pakniat and Vanda’s and Karati et al.’s Schemes
5. The Proposed CLS Scheme
6. Security Proof
7. Performance Evaluation
8. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Al-Riyami, S.S.; Paterson, K.G. Certificateless public key cryptography. In Proceedings of the International Conference on the Theory and Application of Cryptology and Information Security; Springer: Berlin/Heidelberg, Germany, 2003; pp. 452–473. [Google Scholar]
- Yum, D.H.; Lee, P.J. Generic construction of certificateless signature. In Proceedings of the Australasian Conference on Information Security and Privacy; Springer: Berlin/Heidelberg, Germany, 2004; pp. 200–211. [Google Scholar]
- Huang, X.; Susilo, W.; Mu, Y.; Zhang, F. On the security of certificateless signature schemes from Asiacrypt 2003. In Proceedings of the Cryptology and Network Security: 4th International Conference, CANS 2005, Xiamen, China, 14–16 December 2005; Proceedings 4. Springer: Berlin/Heidelberg, Germany, 2005; pp. 13–25. [Google Scholar]
- Choi, K.Y.; Park, J.H.; Lee, D.H. A new provably secure certificateless short signature scheme. Comput. Math. Appl. 2011, 61, 1760–1768. [Google Scholar] [CrossRef]
- He, D.; Chen, J.; Zhang, R. An efficient and provably-secure certificateless signature scheme without bilinear pairings. Int. J. Commun. Syst. 2012, 25, 1432–1442. [Google Scholar] [CrossRef]
- Tian, M.; Huang, L. Cryptanalysis of a certificateless signature scheme without pairings. Int. J. Commun. Syst. 2013, 26, 1375–1381. [Google Scholar] [CrossRef]
- Tsai, J.L.; Lo, N.W.; Wu, T.C. Weaknesses and improvements of an efficient certificateless signature scheme without using bilinear pairings. Int. J. Commun. Syst. 2014, 27, 1083–1090. [Google Scholar] [CrossRef]
- Gong, P.; Li, P. Further improvement of a certificateless signature scheme without pairing. Int. J. Commun. Syst. 2014, 27, 2083–2091. [Google Scholar] [CrossRef]
- Yeh, K.H.; Tsai, K.Y.; Kuo, R.Z.; Wu, T.C. Robust certificateless signature scheme without bilinear pairings. In Proceedings of the 2013 International Conference on IT Convergence and Security (ICITCS), Macao, China, 16–18 December 2013; pp. 1–4. [Google Scholar]
- Wang, L.; Chen, K.; Long, Y.; Mao, X.; Wang, H. A modified efficient certificateless signature scheme without bilinear pairings. In Proceedings of the 2015 International Conference on Intelligent Networking and Collaborative Systems, Taipei, Taiwan, 2–4 September 2015; pp. 82–85. [Google Scholar]
- Yeh, K.H.; Su, C.; Choo, K.K.R.; Chiu, W. A novel certificateless signature scheme for smart objects in the Internet-of-Things. Sensors 2017, 17, 1001. [Google Scholar] [CrossRef] [PubMed]
- Jia, X.; He, D.; Liu, Q.; Choo, K.K.R. An efficient provably-secure certificateless signature scheme for Internet-of-Things deployment. Ad Hoc Netw. 2018, 71, 78–87. [Google Scholar] [CrossRef]
- Karati, A.; Hafizul Islam, S.; Biswas, G. A pairing-free and provably secure certificateless signature scheme. Inf. Sci. 2018, 450, 378–391. [Google Scholar] [CrossRef]
- Pakniat, N.; Vanda, B.A. Cryptanalysis and Improvement of a Pairing-Free Certificateless Signature Scheme. In Proceedings of the 2018 15th International ISC (Iranian Society of Cryptology) Conference on Information Security and Cryptology (ISCISC), Tehran, Iran, 28–29 August 2018; pp. 1–5. [Google Scholar]
- Shim, K.A. Forgery attacks on two provably secure certificateless signature schemes. Inf. Sci. 2020, 521, 81–87. [Google Scholar] [CrossRef]
- Du, H.; Wen, Q.; Zhang, S.; Gao, M. A new provably secure certificateless signature scheme for Internet of Things. Ad Hoc Netw. 2020, 100, 102074. [Google Scholar] [CrossRef]
- Thumbur, G.; Rao, G.S.; Reddy, P.V.; Gayathri, N.B.; Reddy, D.V.R.K. Efficient Pairing-Free Certificateless Signature Scheme for Secure Communication in Resource-Constrained Devices. IEEE Commun. Lett. 2020, 24, 1641–1645. [Google Scholar] [CrossRef]
- Xu, Z.; Luo, M.; Khan, M.K.; Choo, K.K.R.; He, D. Analysis and Improvement of a Certificateless Signature Scheme for Resource-Constrained Scenarios. IEEE Commun. Lett. 2021, 25, 1074–1078. [Google Scholar] [CrossRef]
- Xiang, D.; Li, X.; Gao, J.; Zhang, X. A secure and efficient certificateless signature scheme for Internet of Things. Ad Hoc Netw. 2022, 124, 102702. [Google Scholar] [CrossRef]
- Ma, K.; Zhou, Y.; Wang, Y.; Dong, C.; Xia, Z.; Yang, B.; Zhang, M. An Efficient Certificateless Signature Scheme with Provably Security and Its Applications. IEEE Syst. J. 2023, 17, 5636–5647. [Google Scholar] [CrossRef]
- Feng, T.; Wang, J.; Zheng, L. Blockchain-enhanced efficient and anonymous certificateless signature scheme and its application. Pervasive Mob. Comput. 2024, 105, 101990. [Google Scholar] [CrossRef]
Notation | Operation | Time (ms) |
---|---|---|
A scalar multiplication operation on elliptic curve | 0.334273 | |
A point addition operation on elliptic curve | 0.002042 | |
A modular multiplication operation | 0.000864 | |
A modular addition operation | 0.000455 | |
A modular inversion operation | 0.002742 | |
A general hash operation | 0.002440 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Wei, Z.; Liu, X.; Zhao, H.; Li, Z.; Liu, B. A New Efficient and Provably Secure Certificateless Signature Scheme Without Bilinear Pairings for the Internet of Things. Sensors 2025, 25, 5224. https://doi.org/10.3390/s25175224
Wei Z, Liu X, Zhao H, Li Z, Liu B. A New Efficient and Provably Secure Certificateless Signature Scheme Without Bilinear Pairings for the Internet of Things. Sensors. 2025; 25(17):5224. https://doi.org/10.3390/s25175224
Chicago/Turabian StyleWei, Zhanzhen, Xiaoting Liu, Hong Zhao, Zhaobin Li, and Bowen Liu. 2025. "A New Efficient and Provably Secure Certificateless Signature Scheme Without Bilinear Pairings for the Internet of Things" Sensors 25, no. 17: 5224. https://doi.org/10.3390/s25175224
APA StyleWei, Z., Liu, X., Zhao, H., Li, Z., & Liu, B. (2025). A New Efficient and Provably Secure Certificateless Signature Scheme Without Bilinear Pairings for the Internet of Things. Sensors, 25(17), 5224. https://doi.org/10.3390/s25175224