On the Security of a Lattice-based Linkable Ring Signature for Cloud-Assisted EMRs
Abstract
Recent advances in lattice-based cryptography have seen Chen et al. introduce a linkable ring signature scheme (LLRS) for cloud-assisted electronic medical record systems, claiming dual security properties of linkability and unforgeability (IEEE Trans. Inf. Forensics Secur., doi: 10.1109/TIFS.2024.3455772). Our cryptanalysis reveals critical security flaws in their construction: the scheme fails to satisfy either claimed property. Specifically, we demonstrate universal forgeability through adaptive message attacks and identify defective linkability verification that permits signature origin ambiguity. Following vulnerability demonstrations via concrete attack vectors, we trace these weaknesses to flawed parameter initialization and improper nonce handling in their zero-knowledge proof framework. We conclude with concrete mitigation strategies including strengthened commitment schemes and improved randomness management.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.