The SPEKE Protocol Revisited

The SPEKE Protocol Revisited
复制标题

重新审视 SPEKE 协议

DOI:
--
复制
发表时间:
2014
期刊:
ACM SIGSOFT Symposium on Software Reusability
影响因子:
--
通讯作者:
S. F. Shahandashti
S. F. Shahandashti
中科院分区:
--
文献类型:
--
作者:
F. Hao;S. F. Shahandashti

文献摘要

被引文献

相似文献

SPEKE协议通常被认为是经典的密码认证密钥交换(PAKE)方案之一。它已被纳入国际标准(特别是ISO/IEC 11770-4和IEEE 1363.2)并部署在商业产品中(例如,黑莓)。我们观察到,原始的SPEKE规范与ISO/IEC 11770-4和IEEE 1363.2标准中定义的规范略有不同。我们通过提出针对SPEKE的两种新攻击(模拟攻击和密钥延展性攻击)来说明这些差异具有重要的安全含义。第一种攻击允许攻击者通过与受害者进行两个并行会话,在不知道密码的情况下冒充用户。第二种攻击允许攻击者操纵在两个诚实用户之间建立的会话密钥而不被检测到。这两种攻击都适用于原始的SPEKE方案,在ISO/IEC 11770-4和IEEE 1363.2标准中只有部分解决。我们强调了这两个标准的不足之处,并提出了具体的修改建议。
The SPEKE protocol is commonly considered one of the classic Password Authenticated Key Exchange (PAKE) schemes. It has been included in international standards (particularly, ISO/IEC 11770-4 and IEEE 1363.2) and deployed in commercial products (e.g., Blackberry). We observe that the original SPEKE specification is subtly different from those defined in the ISO/IEC 11770-4 and IEEE 1363.2 standards. We show that those differences have critical security implications by presenting two new attacks on SPEKE: an impersonation attack and a key-malleability attack. The first attack allows an attacker to impersonate a user without knowing the password by engaging in two parallel sessions with the victim. The second attack allows an attacker to manipulate the session key established between two honest users without being detected. Both attacks are applicable to the original SPEKE scheme, and are only partially addressed in the ISO/IEC 11770-4 and IEEE 1363.2 standards. We highlight deficiencies in both standards and suggest concrete changes.