Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges
Review Article  ·  Published: 20 September 2026
Issue cover
ICCK Transactions on Information Security and Cryptography
Volume 2, Issue 3, 2026: 136-158
Review Article Free to Read

Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges

1 Faculty of Computing, Riphah International University, Islamabad 44000, Pakistan
2 Department of Information Technology, The University of Haripur, Haripur 22620, Pakistan
* Corresponding Author: Saddam Hussain, [email protected]
Volume 2, Issue 3
You have access to this article · Limited-Time Free Access

Article Information

Abstract

Proxy signature schemes allow an original signer to delegate signing authority to a proxy signer, supporting flexible authentication in distributed and resource-constrained environments such as cloud computing, blockchain, and Internet of Things (IoT) networks. Although many constructions have been proposed, a large number have later been broken due to flawed design assumptions, weak delegation binding, or the absence of rigorous provable security. This paper surveys proxy signature schemes with a focus on their security weaknesses. {It presents} a taxonomy of existing constructions by cryptographic primitive, delegation mechanism, and proof framework, {and then consolidates} known cryptanalytic results, identifying recurring weaknesses such as forgery, proxy misuse, warrant manipulation, insider threats, and ineffective revocation. {The paper also identifies} schemes that rely on informal or incomplete security arguments rather than formal proofs. {Through comparative analysis across the identity-based, certificateless, and certificate-based paradigms, the survey presents recurring design flaws and outlines open challenges and directions toward secure and efficient proxy signatures.

Graphical Abstract

Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges

Keywords

proxy signature cryptanalysis delegation provable security forgery attack post-quantum cryptography

Data Availability Statement

Not applicable.

Funding

This work was supported without any funding.

Conflicts of Interest

Saddam Hussain served as an Associate Editor of the ICCK Transactions on Information Security and Cryptography at the time of manuscript submission. To ensure the integrity of the peer-review process, Saddam Hussain was not involved in the editorial handling, peer review, or decision-making process for this manuscript, which was handled independently by another editor. The remaining authors declare no conflicts of interest.

AI Use Statement

The authors declare that ChatGPT-5 was used for language editing of the manuscript. The authors have carefully reviewed, revised, and verified the AI-assisted output and take full responsibility for the content of the manuscript.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Mambo, M., Usuda, K., & Okamoto, E. (1996). Proxy signatures: Delegation of the power to sign messages. IEICE transactions on fundamentals of electronics, communications and computer sciences, 79(9), 1338-1354.
    [Google Scholar]
  2. Hussain, S., Tufail, A., Naim, H. A. A. G., Khan, M. A., & Barb, G. (2025). Evaluation of computationally efficient identity-based proxy signatures. IEEE Open Journal of the Computer Society, 6, 846-861.
    [CrossRef] [Google Scholar]
  3. Wu, F., Zhou, B., & Zhang, X. (2023). Identity-based proxy signature with message recovery over NTRU lattice. Entropy, 25(3), 454.
    [CrossRef] [Google Scholar]
  4. Islam, S. H., & Biswas, G. P. (2014). A provably secure identity-based strong designated verifier proxy signature scheme from bilinear pairings. Journal of King Saud University Computer and Information Sciences, 26(1), 55-67.
    [CrossRef] [Google Scholar]
  5. Verma, V., & Sharma, Y. (2023). Identity-Based Designated Verifier Proxy Signature Scheme and Its Application to Health Care. International Conference on Recent Developments in Cyber Security, 271-278. Springer.
    [CrossRef] [Google Scholar]
  6. Mehmood, A., Khan, M. A., Maple, C., & Lloret, J. (2023, October). Zero-knowledge proofs based delegation authentication for industrial Internet of Things in certificateless proxy signatures. In 2023 10th International Conference on Internet of Things: Systems, Management and Security (IOTSMS) (pp. 8-14). IEEE.
    [CrossRef] [Google Scholar]
  7. Qu, Y., & Zeng, J. (2022). Certificateless proxy signcryption in the standard model for a UAV network. IEEE Internet of Things Journal, 9(16), 15116-15127.
    [CrossRef] [Google Scholar]
  8. Zhang, G., Zhou, Y., Liu, X., Yang, B., & Zhang, M. (2026). RCBPS: Revocable Certificate-based Proxy Signature Scheme in the Standard Model for Secure CloudIoT Communications. Computer Networks, 112181.
    [CrossRef] [Google Scholar]
  9. Zhang, G., Zhou, Y., Liu, X., & Yang, B. (2026). Certificate-based proxy signature scheme with revocation for Industrial Internet of Things. Computer Standards & Interfaces, 95, 104045.
    [CrossRef] [Google Scholar]
  10. Hussain, S., Tufail, A., Khan, M. A., & Ullah, F. (2025, October). Complexity Evaluation of Certificate-Based Proxy Signatures. In 2025 2nd International Symposium on AI and Cybersecurity (ISAICS) (pp. 1-6). IEEE.
    [CrossRef] [Google Scholar]
  11. Wu, W., Mu, Y., Susilo, W., Seberry, J., & Huang, X. (2007, July). Identity-based proxy signature from pairings. In International Conference on Autonomic and Trusted Computing (pp. 22-31). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  12. He, D., Chen, Y., & Chen, J. (2013). An efficient certificateless proxy signature scheme without pairing. Mathematical and Computer Modelling, 57(9-10), 2510-2518.
    [CrossRef] [Google Scholar]
  13. Chen, Y. C., Liu, C. L., Horng, G., & Chen, K. C. (2011). A provably secure certificateless proxy signature scheme. International Journal of Innovative Computing, Information and Control, 7(9), 5557-5569. \url{http://www.ijicic.org/ijicic-10-07011.pdf
    [Google Scholar]
  14. Deng, L., Hu, Z., Ruan, Y., & Wang, T. (2022). Provably Secure Certificateless Proxy Signature Scheme in the Standard Model. Journal of Internet Technology, 23(2), 279-288. 10.53106/160792642022032302008
    [Google Scholar]
  15. Lu, Y., & Li, J. (2016). Provably secure certificateless proxy signature scheme in the standard model. Theoretical Computer Science, 639, 42-59.
    [CrossRef] [Google Scholar]
  16. Verma, G. K., Singh, B. B., Kumar, N., Obaidat, M. S., He, D., & Singh, H. (2020). An efficient and provable certificate-based proxy signature scheme for IIoT environment. Information sciences, 518, 142-156.
    [CrossRef] [Google Scholar]
  17. Bannore, A., Patil, R. Y., H. Patil, Y., & Deshpande, H. (2024). Proxy signature-based role delegation scheme: formal analysis and simulation. International Journal of Information Technology, 16(7), 4027-4038.
    [CrossRef] [Google Scholar]
  18. Lin, T. W., & Hsu, C. L. (2025). ID-based proxy signature with key-insulated scheme for portable healthcare devices in 5G-IoHT. Journal of Internet Technology, 26(3), 283-292. \url{https://jit.ndhu.edu.tw/article/view/3167
    [Google Scholar]
  19. Verma, G. K., Singh, B. B., Kumar, N., & He, D. (2019). CB-PS: An efficient short-certificate-based proxy signature scheme for UAVs. IEEE Systems Journal, 14(1), 621-632.
    [CrossRef] [Google Scholar]
  20. He, L., Ma, J., Shen, L., & Wei, D. (2021). Certificateless designated verifier proxy signature scheme for unmanned aerial vehicle networks. Science China Information Sciences, 64(1), 112101.
    [CrossRef] [Google Scholar]

  21. [Google Scholar]

  22. [Google Scholar]
  23. Agarwal, N., Rana, A., & Pandey, J. P. (2016, January). Proxy signatures for secured data sharing. In 2016 6th International Conference-Cloud System and Big Data Engineering (Confluence) (pp. 255-258). IEEE.
    [CrossRef] [Google Scholar]
  24. Hussain, S., Tufail, A., Naim, H. A. A. G., Khan, M. A., & Barb, G. (2026). Exploring the Security Dimensions of Identity-Based Proxy Signature Schemes: A Comprehensive Review. IEEE Open Journal of the Computer Society, 7, 817-834.
    [CrossRef] [Google Scholar]
  25. Li, J., Xu, L., & Zhang, Y. (2009). Provably Secure Certificate-based Proxy Signature Schemes. J. Comput., 4(6), 444-452. \url{https://www.jcomputers.us/vol4/jcp0406-02.pdf
    [Google Scholar]
  26. Qiao, Z., Zhou, Y., Yang, B., Zhang, M., Wang, T., & Xia, Z. (2021). Secure and efficient certificate-based proxy signature schemes for industrial internet of things. IEEE Systems Journal, 16(3), 4719-4730. IEEE.
    [CrossRef] [Google Scholar]
  27. Lal, S., & Verma, V. (2006). Identity based strong designated verifier proxy signature scheme. Cryptography eprint Archive Report 2006/394. \url{https://eprint.iacr.org/2006/394
    [Google Scholar]
  28. Zhang, L., Wu, Q., Qin, B., Domingo-Ferrer, J., Zeng, P., Liu, J., & Du, R. (2013, March). A generic construction of proxy signatures from certificateless signatures. In 2013 IEEE 27th International Conference on Advanced Information Networking and Applications (AINA) (pp. 259-266). IEEE.
    [CrossRef] [Google Scholar]
  29. Zhang, J., & Ji, C. (2008). An Efficient Proxy Signature Scheme with Full-delegation. 2008 IEEE International Conference on Networking, Sensing and Control, 513-518. IEEE.
    [CrossRef] [Google Scholar]
  30. Zhang, L., Zhang, F., & Wu, Q. (2012). Delegation of signing rights using certificateless proxy signatures. Information Sciences, 184(1), 298-309. Elsevier.
    [CrossRef] [Google Scholar]
  31. Wang, G., Bao, F., Zhou, J., & Deng, R. H. (2003, November). Security analysis of some proxy signatures. In International Conference on Information Security and Cryptology (pp. 305-319). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  32. Lee, B., Kim, H., & Kim, K. (2001). Strong proxy signature and its applications. Proceedings of SCIS, 2001, 603-608. \url{http://hdl.handle.net/10203/130232
    [Google Scholar]
  33. Chou, J. S., Hung, S. C., & Chen, Y. (2011). An efficient secure anonymous proxy signature scheme. Cryptology ePrint Archive. \url{https://eprint.iacr.org/2011/498
    [Google Scholar]
  34. Boldyreva, A., Palacio, A., & Warinschi, B. (2012). Secure proxy signature schemes for delegation of signing rights. Journal of Cryptology, 25(1), 57-115.
    [CrossRef] [Google Scholar]
  35. Miller, V. S. (1985, August). Use of elliptic curves in cryptography. In Conference on the theory and application of cryptographic techniques (pp. 417-426). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  36. Choon, J. C., & Hee Cheon, J. (2002, December). An identity-based signature from gap Diffie-Hellman groups. In International workshop on public key cryptography (pp. 18-30). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  37. Diffie, W., & Hellman, M. E. (2022). New directions in cryptography. In Democratizing cryptography: the work of Whitfield Diffie and Martin Hellman (pp. 365-390).
    [CrossRef] [Google Scholar]
  38. Koblitz, N. (1987). Elliptic curve cryptosystems. Mathematics of computation, 48(177), 203-209.
    [CrossRef] [Google Scholar]
  39. Boneh, D., & Franklin, M. (2001, August). Identity-based encryption from the Weil pairing. In Annual international cryptology conference (pp. 213-229). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  40. Bellare, M., & Rogaway, P. (1993, December). Random oracles are practical: A paradigm for designing efficient protocols. In Proceedings of the 1st ACM Conference on Computer and Communications Security (pp. 62-73).
    [CrossRef] [Google Scholar]
  41. Canetti, R., Goldreich, O., & Halevi, S. (2004). The random oracle methodology, revisited. Journal of the ACM (JACM), 51(4), 557-594.
    [CrossRef] [Google Scholar]
  42. Zhang, F., & Kim, K. (2003, June). Efficient ID-based blind signature and proxy signature from bilinear pairings. In Australasian Conference on Information Security and Privacy (pp. 312-323). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  43. Mukherjee, D., Vyavahare, P., & Panchal, M. (2016). An improved ID based proxy signature scheme based on elliptic curve cryptography. In Proc. 10th Int. Conf. Emerg. Secur. Inf. Syst. Technol (pp. 235-240). \url{https://personales.upv.es/thinkmind/dl/conferences/securware/securware_2016/securware_2016_12_30_30117.pdf
    [Google Scholar]
  44. Cao, F., & Cao, Z. (2010, August). An identity based proxy signature scheme secure in the standard model. In 2010 IEEE International Conference on Granular Computing (pp. 67-72). IEEE.
    [CrossRef] [Google Scholar]
  45. Sun, Y., Yu, Y., Zhang, X., & Chai, J. (2013). On the security of an identity-based proxy signature scheme in the standard model. IEICE TRANSACTIONS on Fundamentals of Electronics, Communications and Computer Sciences, 96(3), 721-723.
    [CrossRef] [Google Scholar]
  46. Gu, K., Jia, W., & Jiang, C. (2015). Efficient identity-based proxy signature in the standard model. The Computer Journal, 58(4), 792-807. Oxford University Press.
    [CrossRef] [Google Scholar]
  47. Hu, X., Wang, J., Xu, H., Yang, Y., & Xu, X. (2017). An improved efficient identity-based proxy signature in the standard model. International Journal of Computer Mathematics, 94(1), 22-38. Taylor & Francis.
    [CrossRef] [Google Scholar]
  48. James, S., & Thumbur, G. (2021). Pairing-free identity-based proxy signature scheme with message recovery. International Journal of Information Security and Privacy (IJISP), 15(1), 117-137.
    [CrossRef] [Google Scholar]
  49. Hu, X., Lu, H., Xu, H., Wang, J., & Yang, Y. (2015, May). An efficient identity-based proxy signature scheme in the standard model with tight reduction. In Computational Intelligence in Security for Information Systems Conference (pp. 309-319). Cham: Springer International Publishing.
    [CrossRef] [Google Scholar]
  50. Hu, X., Zhang, X., Wang, J., Xu, H., Tan, W., & Yang, Y. (2017). Secure and efficient identity-based proxy signature scheme in the standard model based on computational Diffie–Hellman problem. Arabian Journal for Science and Engineering, 42(2), 639-649.
    [CrossRef] [Google Scholar]
  51. Sarde, P., & Banerjee, A. (2015). A secure ID-based proxy signature scheme from bilinear pairings. International Journal of Computer Applications, 124(9), 1-4.
    [CrossRef] [Google Scholar]
  52. Hu, X., Xu, H., Wang, J., Tan, W., & Yang, Y. (2019). A generic construction of identity-based proxy signature scheme in the standard model. International Journal of Information and Computer Security, 11(1), 83-100.
    [CrossRef] [Google Scholar]
  53. Okamoto, T., Inomata, A., & Okamoto, E. (2005, April). A proposal of short proxy signature using pairing. In International Conference on Information Technology: Coding and Computing (ITCC'05)-Volume II (Vol. 1, pp. 631-635). IEEE.
    [CrossRef] [Google Scholar]
  54. Zhang, F., & Chen, X. (2005). Attack on Okamoto et al.'s New Short Signature Schemes. Cryptology ePrint Archive. \url{https://eprint.iacr.org/2005/240
    [Google Scholar]
  55. Zhang, J., & Yu, Y. (2014). Short computational Diffie–Hellman‐based proxy signature scheme in the standard model. International Journal of Communication Systems, 27(10), 1894-1907.
    [CrossRef] [Google Scholar]
  56. Yuan, Y. (2015). On the security of a proxy signature scheme in the standard model. International Journal of Communication Systems, 28(4), 675-681.
    [CrossRef] [Google Scholar]
  57. Kang, B., Boyd, C., & Dawson, E. (2009). Identity-based strong designated verifier signature schemes: attacks and new construction. Computers & Electrical Engineering, 35(1), 49-53.
    [CrossRef] [Google Scholar]
  58. Zhang, J., & Mao, J. (2008). A novel ID-based designated verifier signature scheme. Information sciences, 178(3), 766-773.
    [CrossRef] [Google Scholar]
  59. Yang, A. (2010, October). ID-based designated-verifier proxy signature scheme without a trusted party. In 2010 International Conference on Computer Application and System Modeling (ICCASM 2010) (Vol. 7, pp. V7-191). IEEE.
    [CrossRef] [Google Scholar]
  60. Wang, B. (2008). A new identity based proxy signature scheme. Cryptology ePrint Archive. \url{https://eprint.iacr.org/2008/323
    [Google Scholar]
  61. Sha, L. (2015, June). Improvement of an ID-based proxy signature scheme without trusted PKG. In 2015 IEEE/ACIS 16th International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD) (pp. 1-4). IEEE.
    [CrossRef] [Google Scholar]
  62. Lee, J. S., Chang, J. H., & Lee, D. H. (2010). Forgery attacks on Kang et al.’s identity-based strong designated verifier signature scheme and its improvement with security proof. Computers & Electrical Engineering, 36(5), 948-954.
    [CrossRef] [Google Scholar]
  63. Wei, B. D. (2013). A provably secure ID-based designated verifier proxy signature scheme based on DLP. Applied Mechanics and Materials, 411, 721-724.
    [CrossRef] [Google Scholar]
  64. Sarde, P. A. N. K. A. J., & Banerjee, A. M. I. T. A. B. H. (2014). An identity based strong designated verifier proxy signature scheme from bilinear pairings. Int. J. Math. Comput. Appl. Res, 4(6), 1-8.
    [Google Scholar]
  65. Singh, H., & Verma, G. K. (2012). ID-based proxy signature scheme with message recovery. Journal of Systems and Software, 85(1), 209-214.
    [CrossRef] [Google Scholar]
  66. Tian, M., Huang, L., & Yang, W. (2012). Cryptanalysis of an ID-based proxy signature scheme with message recovery. Applied Mathematics & Information Sciences, 6(3), 419-422. \url{https://www.naturalspublishing.com/files/published/97em5p1ly4a6k7.pdf
    [Google Scholar]
  67. Zhou, C. (2015). An improved id-based proxy signature scheme with message recovery. International Journal of Security and Its Applications, 9(9), 151--164. http://dx.doi.org/10.14257/ijsia.2015.9.9.14
    [Google Scholar]
  68. Yoon, E. J., Choi, Y., & Kim, C. (2013, May). New ID-based proxy signature scheme with message recovery. In International Conference on Grid and Pervasive Computing (pp. 945-951). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  69. Asaar, M. R., Salmasizadeh, M., & Susilo, W. (2016). A short ID‐based proxy signature scheme. International Journal of Communication Systems, 29(5), 859-873.
    [CrossRef] [Google Scholar]
  70. Li, X. X., Chen, K. F., & Sun, L. (2005). Certificateless signature and proxy signature schemes from bilinear pairings. Lithuanian Mathematical Journal, 45(1), 76-83.
    [CrossRef] [Google Scholar]
  71. Lu, R., He, D., & Wang, C. (2007, July). Cryptanalysis and improvement of a certificateless proxy signature scheme from bilinear pairings. In Eighth ACIS International Conference on Software Engineering, Artificial Intelligence, Networking, and Parallel/Distributed Computing (SNPD 2007) (Vol. 3, pp. 285-290). IEEE.
    [CrossRef] [Google Scholar]
  72. Ming, Y., & Wang, Y. (2018). Certificateless proxy signature scheme in the standard model. Fundamenta Informaticae, 160(4), 409-445.
    [CrossRef] [Google Scholar]
  73. Zhou, C., Dong, X., Wang, L., & Li, T. (2019). On the Security of a Certificateless Proxy Signature Scheme in the Standard Model. International Journal of Network Security, 21(4), 576-581.
    [CrossRef] [Google Scholar]
  74. Ullah, R., Mehmood, A., Khan, M. A., Maple, C., & Lloret, J. (2024). An optimal secure and reliable certificateless proxy signature for industrial internet of things. Peer-to-Peer Networking and Applications, 17(4), 2205-2220.
    [CrossRef] [Google Scholar]
  75. Ullah, R., Mehmood, A., Khan, M. A., & Ullah, I. (2025). Provably secure multilayers certificateless proxy signature for industrial internet of things. Cluster Computing, 28(5), 312.
    [CrossRef] [Google Scholar]
  76. Yu, Y., Xu, C., Huang, X., & Mu, Y. (2009). An efficient anonymous proxy signature scheme with provable security. Computer Standards & Interfaces, 31(2), 348-353.
    [CrossRef] [Google Scholar]
  77. Chou, J. S. (2012). A novel anonymous proxy signature scheme. Advances in Multimedia, 2012(1), 427961. Wiley Online Library.
    [CrossRef] [Google Scholar]
  78. Padhye, S., & Tiwari, N. (2015). ECDLP-based certificateless proxy signature scheme with message recovery. Transactions on Emerging Telecommunications Technologies, 26(3), 346-354. Wiley Online Library.
    [CrossRef] [Google Scholar]
  79. Shi, W., He, D., & Gong, P. (2013). On the security of a certificateless proxy signature scheme with message recovery. Mathematical Problems in Engineering, 2013(1), 761694.
    [CrossRef] [Google Scholar]
  80. Xu, Z., Luo, M., Vijayakumar, P., Peng, C., & Wang, L. (2022). Efficient certificateless designated verifier proxy signature scheme using UAV network for sustainable smart city. Sustainable Cities and Society, 80, 103771.
    [CrossRef] [Google Scholar]
  81. Yang, W., Weng, J., Huang, X., & Yang, A. (2020). A provably secure certificateless proxy signature scheme against malicious-but-passive KGC attacks. The Computer Journal, 63(8), 1139-1147.
    [CrossRef] [Google Scholar]
  82. Lin, X. J., Wang, Q., Sun, L., Yan, Z., & Liu, P. (2021). Security analysis of the first certificateless proxy signature scheme against malicious-but-passive KGC attacks. The Computer Journal, 64(4), 653-660.
    [CrossRef] [Google Scholar]
  83. Kang, B. G., Park, J. H., & Hahn, S. G. (2004, February). A certificate-based signature scheme. In Cryptographers’ Track at the RSA Conference (pp. 99-111). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  84. Chen, J., & Huang, Z. (2010, December). Certificate-based proxy signature. In 2010 IEEE International Conference on Progress in Informatics and Computing (Vol. 1, pp. 465-468). IEEE.
    [CrossRef] [Google Scholar]
  85. Liang, X. Q., Liu, S. D., Xu, J. F., & Liu, Q. (2010, August). A certificate-based strong designated verifier proxy signature scheme. In 2010 3rd International Conference on Advanced Computer Theory and Engineering (ICACTE) (Vol. 1, pp. V1-614). IEEE.
    [CrossRef] [Google Scholar]
  86. Huang, R., Huang, Z., & Chen, Q. (2014). Provable secure generic construction of proxy signature from certificate-based signature. Open Automation and Control Systems Journal, 6, 566-574. \url{https://www.benthamopenarchives.com/contents/pdf/TOAUTOCJ/TOAUTOCJ-6-566.pdf
    [Google Scholar]
  87. Mahmoodi, A., Mohajery, J., & Salmasizadeh, M. (2016). A certificate‐based proxy signature with message recovery without bilinear pairing. Security and Communication Networks, 9(18), 4983-4991.
    [CrossRef] [Google Scholar]
  88. Verma, V., & Thakur, A. (2019). A Certificate-Based Proxy Signature Without Message Recovery With Bilinear Pairing. International Journal of Scientific & Technology Research, 8(11). \url{https://eprint.iacr.org/2014/010
    [Google Scholar]
  89. Verma, G. K., & Singh, B. (2017). Short certificate-based proxy signature scheme from pairings. Transactions on Emerging Telecommunications Technologies, 28(12), e3214. Wiley Online Library.
    [CrossRef] [Google Scholar]
  90. Zhu, F., Xu, F., Yang, X., Yi, X., & Abuadbba, A. (2022). Cryptanalysis and improvements of an efficient certificate-based proxy signature scheme for IIoT environments. Information Processing Letters, 173, 106170. Elsevier.
    [CrossRef] [Google Scholar]
  91. Park, J. H., & Kim, W. H. (2024). Security weakness of a certificate-based proxy signature scheme for IIoT environments. Information Processing Letters, 183, 106406.
    [CrossRef] [Google Scholar]
  92. Kang, L., Tang, X., Lu, X., & Fan, J. (2007). A short signature scheme in the standard model. Cryptology ePrint Archive. Citeseer. \url{https://eprint.iacr.org/2007/398
    [Google Scholar]
  93. Jiang, Y., Kong, F., & Ju, X. (2010, December). Lattice-based proxy signature. In 2010 International Conference on Computational Intelligence and Security (pp. 382-385). IEEE.
    [CrossRef] [Google Scholar]
  94. Li, W. (2016, September). An identity-based proxy signature scheme from lattices in the standard model. In 2016 International conference on intelligent networking and collaborative systems (INCoS) (pp. 167-172). IEEE.
    [CrossRef] [Google Scholar]
  95. Zhang, L., & Ma, Y. (2014). A Lattice‐Based Identity‐Based Proxy Blind Signature Scheme in the Standard Model. Mathematical Problems in Engineering, 2014(1), 307637.
    [CrossRef] [Google Scholar]
  96. Wu, F., Yao, W., Zhang, X., Wang, W., & Zheng, Z. (2019). Identity‐based proxy signature over NTRU lattice. International journal of communication systems, 32(3), e3867.
    [CrossRef] [Google Scholar]
  97. Yu, H., & Wang, N. (2023). Certificateless network coding proxy signatures from lattice. Frontiers of Computer Science, 17(5), 175810.
    [CrossRef] [Google Scholar]
  98. Li, F., Yang, M., Song, Z., Wang, P., & Li, G. (2023). Post-quantum secure identity-based proxy blind signature scheme on a lattice. Entropy, 25(8), 1157. MDPI.
    [CrossRef] [Google Scholar]
  99. Wang, L., Huang, C., & Cheng, H. (2023). Novel proxy signature from lattice for the post-quantum Internet of Things. Journal of Ambient Intelligence and Humanized Computing, 14(8), 9939-9946.
    [CrossRef] [Google Scholar]
  100. Tian, M., & Huang, L. (2011). Cryptanalysis of a lattice-based proxy signature scheme. arXiv preprint arXiv:1110.4196.
    [CrossRef] [Google Scholar]
  101. Blanchet, B. (2001). An efficient cryptographic protocol verifier based on prolog rules. Proceedings. 14th IEEE Computer Security Foundations Workshop, 2001., 82-96.
    [CrossRef] [Google Scholar]
  102. Blanchet, B. (2016). Modeling and verifying security protocols with the applied pi calculus and ProVerif. Foundations and Trends® in Signal Processing, 1(1-2), 1-135.
    [CrossRef] [Google Scholar]
  103. Meier, S., Schmidt, B., Cremers, C., & Basin, D. (2013, July). The TAMARIN prover for the symbolic analysis of security protocols. In International conference on computer aided verification (pp. 696-701). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  104. Armando, A., Basin, D., Boichut, Y., Chevalier, Y., Compagna, L., Cuéllar, J., ... & Vigneron, L. (2005, July). The AVISPA tool for the automated validation of internet security protocols and applications. In International conference on computer aided verification (pp. 281-285). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  105. Blanchet, B. (2008). A computationally sound mechanized prover for security protocols. IEEE Transactions on Dependable and Secure Computing, 5(4), 193-207.
    [CrossRef] [Google Scholar]
  106. Barthe, G., Grégoire, B., Heraud, S., & Béguelin, S. Z. (2011, August). Computer-aided security proofs for the working cryptographer. In Annual Cryptology Conference (pp. 71-90). Berlin, Heidelberg: Springer Berlin Heidelberg.
    [CrossRef] [Google Scholar]
  107. Goldwasser, S., Micali, S., & Rackoff, C. (1989). The knowledge complexity of interactive proof systems. SIAM Journal on Computing, 18(1), 186-208.
    [CrossRef] [Google Scholar]
  108. Bender, A., Katz, J., & Morselli, R. (2009). Ring signatures: Stronger definitions, and constructions without random oracles. Journal of Cryptology, 22(1), 114-138.
    [CrossRef] [Google Scholar]
  109. Chathurangi, M., Li, Q., & Foo, E. (2025). On advances of anonymous credentials—from traditional to post-quantum. Cryptography, 9(1), 8. MDPI.
    [CrossRef] [Google Scholar]

Cite This Article

APA Style
Hussain, S., & Nayab (2026). Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges. ICCK Transactions on Information Security and Cryptography, 2(3), 136-158. https://doi.org/10.62762/TISC.2026.211619
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Hussain, Saddam
AU  - Nayab
PY  - 2026
DA  - 2026/09/20
TI  - Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges
JO  - ICCK Transactions on Information Security and Cryptography
T2  - ICCK Transactions on Information Security and Cryptography
JF  - ICCK Transactions on Information Security and Cryptography
VL  - 2
IS  - 3
SP  - 136
EP  - 158
DO  - 10.62762/TISC.2026.211619
UR  - https://www.icck.org/article/abs/TISC.2026.211619
KW  - proxy signature
KW  - cryptanalysis
KW  - delegation
KW  - provable security
KW  - forgery attack
KW  - post-quantum cryptography
AB  - Proxy signature schemes allow an original signer to delegate signing authority to a proxy signer, supporting flexible authentication in distributed and resource-constrained environments such as cloud computing, blockchain, and Internet of Things (IoT) networks. Although many constructions have been proposed, a large number have later been broken due to flawed design assumptions, weak delegation binding, or the absence of rigorous provable security. This paper surveys proxy signature schemes with a focus on their security weaknesses. {It presents} a taxonomy of existing constructions by cryptographic primitive, delegation mechanism, and proof framework, {and then consolidates} known cryptanalytic results, identifying recurring weaknesses such as forgery, proxy misuse, warrant manipulation, insider threats, and ineffective revocation. {The paper also identifies} schemes that rely on informal or incomplete security arguments rather than formal proofs. {Through comparative analysis across the identity-based, certificateless, and certificate-based paradigms, the survey presents recurring design flaws and outlines open challenges and directions toward secure and efficient proxy signatures.
SN  - 3070-2429
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Hussain2026Security,
  author = {Saddam Hussain and Nayab},
  title = {Security Vulnerabilities in Proxy Signature Schemes: Cryptanalysis, Design Weaknesses, and Open Challenges},
  journal = {ICCK Transactions on Information Security and Cryptography},
  year = {2026},
  volume = {2},
  number = {3},
  pages = {136-158},
  doi = {10.62762/TISC.2026.211619},
  url = {https://www.icck.org/article/abs/TISC.2026.211619},
  abstract = {Proxy signature schemes allow an original signer to delegate signing authority to a proxy signer, supporting flexible authentication in distributed and resource-constrained environments such as cloud computing, blockchain, and Internet of Things (IoT) networks. Although many constructions have been proposed, a large number have later been broken due to flawed design assumptions, weak delegation binding, or the absence of rigorous provable security. This paper surveys proxy signature schemes with a focus on their security weaknesses. {It presents} a taxonomy of existing constructions by cryptographic primitive, delegation mechanism, and proof framework, {and then consolidates} known cryptanalytic results, identifying recurring weaknesses such as forgery, proxy misuse, warrant manipulation, insider threats, and ineffective revocation. {The paper also identifies} schemes that rely on informal or incomplete security arguments rather than formal proofs. {Through comparative analysis across the identity-based, certificateless, and certificate-based paradigms, the survey presents recurring design flaws and outlines open challenges and directions toward secure and efficient proxy signatures.},
  keywords = {proxy signature, cryptanalysis, delegation, provable security, forgery attack, post-quantum cryptography},
  issn = {3070-2429},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
0
Scopus
0
Views
8
PDF Downloads
3

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

Institute of Central Computation and Knowledge (ICCK) or its licensor holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
ICCK Transactions on Information Security and Cryptography
ICCK Transactions on Information Security and Cryptography
ISSN: 3070-2429 (Online)
Portico
Preserved at
Portico