On the Security of Some Password-Based Key Agreement Schemes
On the Security of Some Password-Based Key Agreement Schemes
复制标题
几种基于密码的密钥协商方案的安全性
DOI:
--
复制
发表时间:
2005
期刊:
影响因子:
--
通讯作者:
C. Mitchell
中科院分区:
文献类型:
--
作者:
Qiang Tang;C. Mitchell
In this paper we show that three potential security vulnerabilities exist in the strong password-only authenticated key exchange scheme due to Jablon. Two standardised schemes based on Jablon’s scheme, namely the first password-based key agreement mechanism in ISO/IEC FCD 11770-4 and the scheme BPKAS-SPEKE in IEEE P1363.2 also suffer from some of these security vulnerabilities. We further show that other password-based key agreement mechanisms, including those in ISO/IEC FCD 11770-4 and IEEE P1363.2, also suffer from these security vulnerabilities. Finally, we propose means to remove these security vulnerabilities.