Efficient provably secure password-based explicit authenticated key agreement

Efficient provably secure password-based explicit authenticated key agreement
复制标题

DOI:
10.1016/j.pmcj.2015.06.008
复制
发表时间:
2015-12-01
影响因子:
4.3
通讯作者:
Lee, Jong-Hyouk
Lee, Jong-Hyouk
中科院分区:
计算机科学3区
文献类型:
--
作者:
Ruan, Ou;Kumar, Neeraj;Lee, Jong-Hyouk

文献摘要

被引文献

相似文献

基于密码的认证密钥协商使多方能够使用短的低熵密码在不可靠和不安全的公共网络上建立共享的加密强密钥。即使在物联网(IoT)环境中,也肯定需要这种经过身份验证的密钥协议,因为不需要额外的设备。基于密码的显式认证密钥协商(EAKA)在文献中只有很少的建议。最近,Zheng等人提出了一种基于3轮密码的EAKA协议。在本文中,我们揭示了他们的协议是容易受到模仿攻击,和使用的安全定义没有正式处理。在此基础上,我们对基于口令的两方EAKA协议的安全性进行了形式化定义,并对Zheng等人的结构进行了改进,消除了其安全漏洞。使用一个新的安全模型形式化地证明了该方案的安全性。(C)2015爱思唯尔B.V.保留所有权利。
A password-based authenticated key agreement enables several parties to establish a shared cryptographically strong key over a public unreliable and insecure network using short low-entropy passwords. This authenticated key agreement is definitely required even in Internet of Things (IoT) environments, since no additional device is required. There are only few proposals reported in literature for password-based explicit authenticated key agreement (EAKA). Recently, Zheng et al. proposed a 3-round password-based EAKA protocol. In this paper, we reveal that their protocol is vulnerable to impersonation attack, and the used security definition is not formally treated. We then formalize the security definition of two-party password-based EAKA protocol and improve the construction of Zheng et al. to eliminate its security vulnerabilities. The security of the proposal is formally proved using a new security model. (C) 2015 Elsevier B.V. All rights reserved.