On the Security of Some Password-Based Key Agreement Schemes

On the Security of Some Password-Based Key Agreement Schemes
复制标题

几种基于密码的密钥协商方案的安全性

DOI:
--
复制
发表时间:
2005
期刊:
International Conference on Computational Intelligence and Security
影响因子:
--
通讯作者:
C. Mitchell
C. Mitchell
中科院分区:
--
文献类型:
--
作者:
Qiang Tang;C. Mitchell

文献摘要

被引文献

相似文献

本文证明了Jablon的强密码认证密钥交换方案存在三个潜在的安全漏洞。两个基于Jablon方案的标准化方案,即ISO/IEC FCD 11770-4中的第一个基于密码的密钥协商机制和IEEE P1363.2中的BPKAS-Speke方案也存在这些安全漏洞。我们进一步指出,其他基于口令的密钥协商机制,包括ISO/IEC FCD 11770-4和IEEEP1363.2中的那些机制,也存在这些安全漏洞。最后,我们提出了消除这些安全漏洞的方法。
In this paper we show that three potential security vulnerabilities exist in the strong password-only authenticated key exchange scheme due to Jablon. Two standardised schemes based on Jablon’s scheme, namely the first password-based key agreement mechanism in ISO/IEC FCD 11770-4 and the scheme BPKAS-SPEKE in IEEE P1363.2 also suffer from some of these security vulnerabilities. We further show that other password-based key agreement mechanisms, including those in ISO/IEC FCD 11770-4 and IEEE P1363.2, also suffer from these security vulnerabilities. Finally, we propose means to remove these security vulnerabilities.