Authenticated Key Exchange Secure against Dictionary Attacks

Authenticated Key Exchange Secure against Dictionary Attacks
复制标题

DOI:
10.1007/3-540-45539-6_11
复制
发表时间:
2000-05
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
M. Bellare;D. Pointcheval;P. Rogaway
M. Bellare;D. Pointcheval;P. Rogaway
中科院分区:
其他
文献类型:
--
作者:
M. Bellare;D. Pointcheval;P. Rogaway

文献摘要

被引文献

相似文献

基于密码的认证密钥交换 (AKE) 协议被设计为即使使用从很小的空间提取的密码,对手很可能离线枚举所有可能的密码,也能正常工作。虽然已经提出了几种这样的协议,但基本理论一直滞后。我们首先为这个问题定义一个模型,该模型足够丰富,可以处理密码猜测、前向保密、服务器泄露和会话密钥丢失。一个模型可用于定义各种目标。我们将 AKE(“隐式”身份验证)作为“基本”目标,并为其以及实体身份验证目标给出定义。然后我们证明 Bellovin 和 Merritt 的加密密钥交换 (EKE) 协议核心思想的正确性:我们在理想密码模型中证明 EKE 核心的双流协议的安全性。
Password-based protocols for authenticated key exchange (AKE) are designed to work despite the use of passwords drawn from a space so small that an adversary might well enumerate, off line, all possible passwords. While several such protocols have been suggested, the underlying theory has been lagging. We begin by defining a model for this problem, one rich enough to deal with password guessing, forward secrecy, server compromise, and loss of session keys. The one model can be used to define various goals. We take AKE (with “implicit” authentication) as the “basic” goal, and we give definitions for it, and for entity-authentication goals as well. Then we prove correctness for the idea at the center of the Encrypted Key-Exchange (EKE) protocol of Bellovin and Merritt: we prove security, in an ideal-cipher model, of the two-flow protocol at the core of EKE.