期刊:IEEE Transactions on Dependable and Secure Computing [Institute of Electrical and Electronics Engineers] 日期:2023-09-22卷期号:21 (4): 4302-4303
标识
DOI:10.1109/tdsc.2023.3318296
摘要
In Wireless body area networks(WBANs), the physiological parameters monitored by wearable devices are sensitive data of patients. To ensure the privacy of such data, Shen et al proposed a multi-receiver certificateless generalized signcryption scheme to support multidisciplinary team treatment. Although they claim that their scheme can resist Type I attacks and provide the unlinkability of ciphertext, our analysis found that their scheme is insecure. Specifically, it is neither resistant to public key replacement in Type I attacks, nor does it satisfy the claimed unlinkability of ciphertext. After giving the corresponding attacks, we analyze the reasons underlying these attacks and provide the corresponding suggestions to overcome them.