Cryptanalysis and improvement of Petersen-Michels signcryption scheme

Petersen and Michels showed that Zheng's signcryption schemes lose confidentiality to gain nonrepudiation. They also proposed another signcryption scheme modified from a signature scheme giving message recovery. The authors show that the Petersen-Michels scheme still violates the unforgeability property, and propose an improvement that overcomes the security leak inherent in the scheme. The improvement is as efficient as previous signcryption schemes with respect to both the computational cost and the communication overhead.