首页> 外文会议>Applied Cryptography and Network Security >Analysis of EAP-GPSK Authentication Protocol
【24h】

Analysis of EAP-GPSK Authentication Protocol

机译:EAP-GPSK认证协议分析

获取原文
获取原文并翻译 | 示例

摘要

The EAP-GPSK protocol is a lightweight, flexible authentication protocol relying on symmetric key cryptography. It is part of an ongoing IETF process to develop authentication methods for the EAP framework. We analyze the protocol and find three weaknesses: a repairable Denial-of-Service attack, an anomaly with the key derivation function used to create a short-term master session key, and a ciphersuite downgrading attack. We propose fixes to these anomalies, and use a finite-state verification tool to search for remaining problems after making these repairs. We then prove the fixed version correct using a protocol verification logic. We discussed the attacks and our suggested fixes with the authors of the specification document which has subsequently been modified to include our proposed changes.
机译:EAP-GPSK协议是一种轻量级的,灵活的身份验证协议,它依赖于对称密钥加密。它是正在进行的IETF流程的一部分,旨在为EAP框架开发身份验证方法。我们分析该协议并发现三个弱点:可修复的拒绝服务攻击,具有用于创建短期主会话密钥的密钥派生功能的异常以及密码套件降级攻击。我们提出对这些异常的修复方法,并使用有限状态验证工具在进行这些修复后搜索剩余的问题。然后,我们使用协议验证逻辑证明固定版本正确。我们与规范文档的作者讨论了攻击和建议的修复程序,随后对该规范文件进行了修改以包括我们建议的更改。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号