期刊文献+

Off-Line Dictionary Attack on Password-Based Authenticated Key Exchange Protocols

Off-Line Dictionary Attack on Password-Based Authenticated Key Exchange Protocols
原文传递
导出
摘要 In 2010,Lee et al proposed two simple and efficient three-party password-authenticated key exchange protocols that had been proven secure in the random oracle model.They argued that the two protocols could resist offline dictionary attacks.Indeed,the provable approach did not provide protection against off-line dictionary attacks.This paper shows that the two protocols are vulnerable to off-line dictionary attacks in the presence of an inside attacker because of an authentication flaw.This study conducts a detailed analysis on the flaw in the protocols and also shows how to eliminate the security flaw. In 2010,Lee et al proposed two simple and efficient three-party password-authenticated key exchange protocols that had been proven secure in the random oracle model.They argued that the two protocols could resist offline dictionary attacks.Indeed,the provable approach did not provide protection against off-line dictionary attacks.This paper shows that the two protocols are vulnerable to off-line dictionary attacks in the presence of an inside attacker because of an authentication flaw.This study conducts a detailed analysis on the flaw in the protocols and also shows how to eliminate the security flaw.
出处 《Wuhan University Journal of Natural Sciences》 CAS 2012年第6期468-472,共5页 武汉大学学报(自然科学英文版)
基金 Supported by the Natural Science Foundation of Jiangsu Province (Key Program) (BK2011023)
关键词 key exchange PASSWORD OFF-LINE dictionary attack provable security key exchange password off-line dictionary attack provable security
  • 相关文献

参考文献18

  • 1Bellovin S, Merritt M. Encrypted key exchange: Passwords based protocols secure against dictionary attacks [C]//Proceedings of the IEEE Symposium on Security and Privacy. Washington D C: IEEE Press, 1992: 72-84.
  • 2DENG Shaofeng LI Yifa DENG Yiqun.An Efficient Two-Party Key Exchange Protocol with Strong Security[J].Wuhan University Journal of Natural Sciences,2010,15(3):267-271. 被引量:2
  • 3Wen H A, Lin C L, Hwang T. Provably secure authenticated key exchange protocols for low power computing clients [J]. Computers Security, 2006, 25(2): 106-113.
  • 4Abdalla M, Pointcheval D. Interactive Diffie-Hellman assumptions with applications to password-based authentication [C]//Proc of Financial Cryptography and Data Security 2005(LNCS 3570). Berlin: Springer- Verlag, 2005: 341-356.
  • 5Abdalla M, Fouque P A, Poimcheval D. Password-based authenticated key exchange in the three-party setting [C]//Proc of the PKC'05(LNCS 3386). Berlin: Springer-Verlag, 2005: 65-84.
  • 6Bellare M, Pointcheval D, Rogaway P. Authenticated key exchange secure against dictionary attacks [C]//Advances in Cryptology-Eurocrypt. Berlin: Springer-Verlag, 2000: 139- 155.
  • 7Bellare M, Rogaway P. Provably secure sessioa key distribution-the three party case [C]//Proc of27th ACMSymposium on Theory of Computing (STOC'95). New York: ACM Press, 1995: 57-66.
  • 8Nam J, Lee Y, Kim Set al. Security weakness in a three- party pairing-based protocol for password authenticated key exchange [J]. Information Sciences, 2007, 177(6): 1364-1375.
  • 9Lu R, Cao Z. Simple three-party key exchange protocol [J]. Computers and Security, 2007, 26(1 ): 94-97.
  • 10Abdalla M, Pointcheval D. Simple password-based encrypted key exchange protocols [C]//Proceedings of the CT-RSA '05, (LNCS 3376). Berlin: Springer-Verlag, 2005: 191-208.

二级参考文献5

共引文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部