Cryptanalysis and improvement of password-authenticated key agreement for session initiation protocol using smart cards

Cryptanalysis and improvement of password-authenticated key agreement for session initiation protocol using smart cards
复制标题

DOI:
10.1002/sec.951
复制
发表时间:
2014-12
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
Liping Zhang;Shanyu Tang;Zhihua Cai
Liping Zhang;Shanyu Tang;Zhihua Cai
中科院分区:
其他
文献类型:
--
作者:
Liping Zhang;Shanyu Tang;Zhihua Cai

文献摘要

相似文献

会话发起协议(SIP)是基于Internet协议的通信中最常用的会话处理协议之一,其安全性变得越来越重要。最近,张等人提出了自己的观点。提出了一种基于口令认证的SIP密钥协商协议,利用智能卡保护用户之间的VoIP通信。它们的协议具有相互认证、不需要密码表、口令可自由更新等特点。在本研究中,我们对Zhang等人的S协议进行了密码分析,发现他们的协议虽然可以抵抗其他几种攻击,但仍然容易受到冒充攻击,恶意攻击者可以计算其他用户的私钥,然后冒充用户欺骗服务器。此外,我们还提出了一种改进的口令认证密钥协商协议,该协议克服了Zhang等人的S协议的弱点,更适合IP语音通信。版权所有©2014 John Wiley&Sons,Ltd.
Session Initiation Protocol (SIP) is one of the most commonly used protocols for handling sessions for over Internet Protocol based communications, and the security of SIP is becoming increasingly important. Recently, Zhang et al. proposed a password-authenticated key agreement protocol for SIP by using smart cards to protect the VoIP communications between users. Their protocol provided some unique features, such as mutual authentication, no password table needed, and password updating freely. In this study, we performed cryptanalysis of Zhang et al.'s protocol and found that their protocol was vulnerable to the impersonation attack although the protocol could withstand several other attacks. A malicious attacker could compute other users' privacy keys and then impersonated the users to cheat the SIP server. Furthermore, we proposed an improved password-authentication key agreement protocol for SIP, which overcame the weakness of Zhang et al.'s protocol and was more suitable for Voice over Internet Protocol communications. Copyright © 2014 John Wiley & Sons, Ltd.