Analysis of the SPEKE password-authenticated key exchange protocol

Analysis of the SPEKE password-authenticated key exchange protocol
复制标题

SPEKE密码认证密钥交换协议分析

DOI:
--
复制
发表时间:
2004
期刊:
IEEE Communications Letters
影响因子:
--
通讯作者:
Muxiang Zhang
Muxiang Zhang
中科院分区:
--
文献类型:
--
作者:
Muxiang Zhang

文献摘要

被引文献

相似文献

在这封信中,我们展示了对于Speke口令认证的密钥交换协议,攻击者能够使用一次模拟尝试来测试多个可能的口令。特别地,当口令是短的个人识别码(PIN)时,我们证明了完全受限的Speke容易受到口令猜测攻击。我们的分析与Speke协议似乎至少与Bellovin-Merritt eke协议一样强大的说法相矛盾。对于EKE,攻击者在每次模拟尝试中最多只能获得一个可能的密码信息。
In this letter, we show that for the SPEKE password-authenticated key exchange protocol, an adversary is able to test multiple possible passwords using a single impersonation attempt. In particular, when passwords are short Personal Identification Numbers (PINs), we show that a fully-constrained SPEKE is susceptible to password guessing attack. Our analysis contradicts the claim that the SPEKE protocol appears to be at least as strong as the Bellovin-Merritt EKE protocol. For EKE, an adversary can gain information about at most one possible password in each impersonation attempt.