Forgeability of Wang-Tang-Li s ID-Based Restrictive Partially Blind Signature Scheme

Sheng-Li Liu{1,4, Xiao-Feng Chen2, and Fang-Guo Zhang3   

  1. 1Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China 2Department of Computer Science, School of Information Science and Technology, Sun Yat-Sen University, Guangzhou 510275, China 3Department of Electronics and Communication Engineering, School of Information Science and Technology, Sun Yat-Sen University, Guangzhou 510275, China 4State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100080, China
  • Received:2007-06-15 Revised:2007-11-20 Online:2008-03-15 Published:2008-03-10

Restrictive partially blind signature (RPBS) plays an important role in designing secure electronic cash system. Very recently, Wang, Tang and Li proposed a new ID-based restrictive partially blind signature (ID-RPBS) and gave the security proof. In this paper, we present a cryptanalysis of the scheme and show that the signature scheme does not satisfy the property of {unforgeability} as claimed. More precisely, a user can forge a valid message-signature pair $({\it ID}, {\it msg}, {\bf info'}, \sigma')$ instead of the original one $({\it ID}, {\it msg}, {\bf info}, \sigma)$, where {\bf info} is the original common agreed information and ${\bf info}'\neq {\bf info}$. Therefore, it will be much dangerous if Wang-Tang-Li's ID-RPBS scheme is applied to the off-line electronic cash system. For example, a bank is supposed to issue an electronic coin (or bill) of \$100 to a user, while the user can change the denomination of the coin (bill) to any value, say \$100\,000\,000, at his will.

