首页 | 本学科首页   官方微博 | 高级检索  
     

对两个口令认证密钥交换协议的安全性分析
引用本文:胡学先,刘文芬,张振峰. 对两个口令认证密钥交换协议的安全性分析[J]. 计算机工程与应用, 2010, 46(18): 18-20. DOI: 10.3778/j.issn.1002-8331.2010.18.007
作者姓名:胡学先  刘文芬  张振峰
作者单位:1.信息工程大学 信息工程学院,郑州 450002 2.中国科学院 软件研究所 信息安全国家重点实验室,北京100190
基金项目:国家高技术研究发展计划(S63),国家自然科学基金 
摘    要:口令认证密钥交换协议使得仅共享低熵口令的用户可以通过不安全的信道安全地协商出高熵的会话密钥,由于实用性较强受到了密码学研究者的广泛关注。对最近在“标准模型下高效的基于口令认证密钥协商协议”一文中提出的协议以及在“基于验证元的三方口令认证密钥交换协议”一文中提出的协议进行了分析,指出这两个口令认证密钥交换协议都是不安全的,难于抵抗离线字典攻击,进一步分析了原协议设计或安全性证明中被疏忽之处。

关 键 词:密钥交换协议  可证明安全  口令认证  离线字典攻击  
收稿时间:2010-03-12
修稿时间:2010-5-11 

Cryptanalysis of two password authenticated key exchange protocols
HU Xue-xian,LIU Wen-fen,ZHANG Zhen-feng. Cryptanalysis of two password authenticated key exchange protocols[J]. Computer Engineering and Applications, 2010, 46(18): 18-20. DOI: 10.3778/j.issn.1002-8331.2010.18.007
Authors:HU Xue-xian  LIU Wen-fen  ZHANG Zhen-feng
Affiliation:1.Department of Information Engineering,Information Engineering University,Zhengzhou 450002,China 2.State Key Laboratory of Information Security,Institute of Software,Chinese Academy of Sciences,Beijing 100190,China
Abstract:Password authenticated key exchange protocol can be used for two parties sharing only a low-entropy password to establish high entropy shared keys.It has been extensively studied for its great application prosperity.In this paper,cryptanalysis of a protocol proposed by Shu et al. in the paper of "Provable Secure Encrypted Key Exchange Protocol under Standard Model" ,and a protocol proposed by Li et al. in the paper of "Verifier-Based Password Authenticated Key Exchange for Three Party" has been presented.Concrete off-line dictionary attacks in which an outside adversary traverses the password dictionary and verifies its guess in off-line manner are also presented.Further,the errors in the original security proof are also analyzed.
Keywords:key exchange protocol  provable security  password authenticated  off-line dictionary attack
本文献已被 维普 万方数据 等数据库收录!
点击此处可从《计算机工程与应用》浏览原始摘要信息
点击此处可从《计算机工程与应用》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号