首页> 外文期刊>International Journal of Soft Computing and Software Engineering >Cryptanalysis of three Provably Secure Password Authenticated Key Exchange Protocols in the three-party Setting
【24h】

Cryptanalysis of three Provably Secure Password Authenticated Key Exchange Protocols in the three-party Setting

机译:在三方设置中对三种可通过安全密码验证的密钥交换协议进行密码分析

获取原文
           

摘要

Three-party Password Authenticated Key Exchange (3PAKE) protocols play a key role in providing security goals in communications. They enable two entities to share a common session key in an authentic manner based on a low entropy human-memorable password. In 2010, Lee and Hwang proposed S-IA-3PAKE and S-EA-3PAKE protocols based on the SPAKE protocol developed by Abdalla and Pointcheval. In 2011, Chang et al. presented an efficient three-party Password Authenticated Key Exchange Protocol and its parallel version based on LHL-3PAKE protocol proposed by Lee et al. In this paper, it is shown that both supposedly provably secure S-IA-3PAKE and S-EA-3PAKE protocols are vulnerable to serious threats such as Unknown Key Share (UKS) and password compromise impersonation attacks. It is also shown that the provably secure protocol of Chang et al. and its parallel version suffer from password compromise impersonation and ephemeral key compromise impersonation attacks. Indeed, our results highlight the need of more attention and precision during defining the provable security models and constructing proofs in this method, because there are still considerable gaps between what can be proven based on formal security models and what are actually secure in use.
机译:三方密码验证密钥交换(3PAKE)协议在提供通信安全目标方面起着关键作用。它们使两个实体能够基于低熵,易于记忆的密码以真实的方式共享公共会话密钥。 Lee和Hwang在2010年基于Abdalla和Pointcheval开发的SPAKE协议提出了S-IA-3PAKE和S-EA-3PAKE协议。 2011年,Chang等。提出了一种有效的三方密码验证密钥交换协议及其基于Lee等人提出的LHL-3PAKE协议的并行版本。在本文中,表明了据称可证明是安全的S-IA-3PAKE和S-EA-3PAKE协议都容易受到诸如未知密钥共享(UKS)和密码泄露模拟攻击等严重威胁的攻击。还显示了Chang等人的可证明安全的协议。而其并行版本则遭受密码泄露模拟和短暂密钥泄露模拟攻击。确实,我们的结果强调了在定义可证明的安全模型和以此方法构造证明期间,需要更多的关注和准确性,因为在基于正式安全模型的可证明内容与实际使用的安全性之间仍然存在相当大的差距。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号