摘要
针对服务器泄漏攻击,给出了抵抗这种攻击的方法,提出了一个新的基于口令的认证密钥协商协议。在该方案中,用户记住自己的口令,而服务器仅仅存储与口令对应的验证信息。分析结果表明,该方案可以抵抗服务器泄漏攻击、字典攻击和Denning-Sacco攻击等,并且具有前向安全性等性质。
Attack, a method of resisting server compromise attack is given and a new password-based authenticated key agreement protocol is proposed. In this protocol, one side (the client) stores a plaintext version of the password, while the other side (the server) only stores a verifier for the password. The analysis of this new protocol shows that the protocol is secure against server compromise attack, dictionary attack,and the Denning-Sacco attack, and provides the property of the perfect forward secrecy.
出处
《电子科技大学学报》
EI
CAS
CSCD
北大核心
2008年第1期17-19,共3页
Journal of University of Electronic Science and Technology of China
基金
国家自然科学基金(60473027)
关键词
字典攻击
密钥协商
口令认证
服务器泄漏攻击
dictiona
y attack
key agreement
password authentication
server compromise attack