• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

关于一种无服务器公钥的简单三方密钥交换协议的安全性

On the security of a simple three-party key exchange protocol without server's public keys.

作者信息

Nam Junghyun, Choo Kim-Kwang Raymond, Park Minkyu, Paik Juryon, Won Dongho

机构信息

Department of Computer Engineering, Konkuk University, 268 Chungwondaero, Chungju, Chungcheongbuk-do 380-701, Republic of Korea.

Information Assurance Research Group, Advanced Computing Research Centre, University of South Australia, Mawson Lakes, SA 5095, Australia.

出版信息

ScientificWorldJournal. 2014;2014:479534. doi: 10.1155/2014/479534. Epub 2014 Sep 1.

DOI:10.1155/2014/479534
PMID:25258723
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC4165805/
Abstract

Authenticated key exchange protocols are of fundamental importance in securing communications and are now extensively deployed for use in various real-world network applications. In this work, we reveal major previously unpublished security vulnerabilities in the password-based authenticated three-party key exchange protocol according to Lee and Hwang (2010): (1) the Lee-Hwang protocol is susceptible to a man-in-the-middle attack and thus fails to achieve implicit key authentication; (2) the protocol cannot protect clients' passwords against an offline dictionary attack; and (3) the indistinguishability-based security of the protocol can be easily broken even in the presence of a passive adversary. We also propose an improved password-based authenticated three-party key exchange protocol that addresses the security vulnerabilities identified in the Lee-Hwang protocol.

摘要

认证密钥交换协议对于保障通信安全至关重要,目前已广泛应用于各种实际网络应用中。在这项工作中,我们揭示了Lee和Hwang(2010)提出的基于密码的认证三方密钥交换协议中以前未公开的主要安全漏洞:(1)Lee-Hwang协议容易受到中间人攻击,因此无法实现隐式密钥认证;(2)该协议无法保护客户端密码免受离线字典攻击;(3)即使在存在被动对手的情况下,该协议基于不可区分性的安全性也很容易被破解。我们还提出了一种改进的基于密码的认证三方密钥交换协议,该协议解决了Lee-Hwang协议中发现的安全漏洞。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cec/4165805/67a231ed0e83/TSWJ2014-479534.002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cec/4165805/869f44ee4fb9/TSWJ2014-479534.001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cec/4165805/67a231ed0e83/TSWJ2014-479534.002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cec/4165805/869f44ee4fb9/TSWJ2014-479534.001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/0cec/4165805/67a231ed0e83/TSWJ2014-479534.002.jpg

相似文献

1
On the security of a simple three-party key exchange protocol without server's public keys.关于一种无服务器公钥的简单三方密钥交换协议的安全性
ScientificWorldJournal. 2014;2014:479534. doi: 10.1155/2014/479534. Epub 2014 Sep 1.
2
Security enhanced anonymous multiserver authenticated key agreement scheme using smart cards and biometrics.使用智能卡和生物特征识别技术的安全增强型匿名多服务器认证密钥协商方案
ScientificWorldJournal. 2014;2014:281305. doi: 10.1155/2014/281305. Epub 2014 Sep 8.
3
Password-only authenticated three-party key exchange proven secure against insider dictionary attacks.仅通过密码认证的三方密钥交换被证明对内部人员字典攻击具有安全性。
ScientificWorldJournal. 2014;2014:802359. doi: 10.1155/2014/802359. Epub 2014 Sep 18.
4
Password-only authenticated three-party key exchange with provable security in the standard model.在标准模型中具有可证明安全性的仅密码认证三方密钥交换。
ScientificWorldJournal. 2014;2014:825072. doi: 10.1155/2014/825072. Epub 2014 Apr 14.
5
Secure verifier-based three-party authentication schemes without server public keys for data exchange in telecare medicine information systems.用于远程医疗信息系统中数据交换的、无需服务器公钥的基于安全验证器的三方认证方案。
J Med Syst. 2014 May;38(5):30. doi: 10.1007/s10916-014-0030-4. Epub 2014 Apr 8.
6
Security and efficiency enhancement of an anonymous three-party password-authenticated key agreement using extended chaotic maps.使用扩展混沌映射增强匿名三方密码认证密钥协商的安全性和效率。
PLoS One. 2018 Oct 5;13(10):e0203984. doi: 10.1371/journal.pone.0203984. eCollection 2018.
7
Provably-secure (Chinese government) SM2 and simplified SM2 key exchange protocols.可证明安全的(中国政府)SM2及简化SM2密钥交换协议。
ScientificWorldJournal. 2014;2014:825984. doi: 10.1155/2014/825984. Epub 2014 Sep 2.
8
Three-party authenticated key agreements for optimal communication.用于优化通信的三方认证密钥协商
PLoS One. 2017 Mar 29;12(3):e0174473. doi: 10.1371/journal.pone.0174473. eCollection 2017.
9
Security analysis and improvement of an anonymous authentication scheme for roaming services.漫游服务匿名认证方案的安全性分析与改进
ScientificWorldJournal. 2014;2014:687879. doi: 10.1155/2014/687879. Epub 2014 Sep 11.
10
The framework for simulation of bioinspired security mechanisms against network infrastructure attacks.针对网络基础设施攻击的生物启发式安全机制的模拟框架。
ScientificWorldJournal. 2014;2014:172583. doi: 10.1155/2014/172583. Epub 2014 Aug 31.

引用本文的文献

1
Password-only authenticated three-party key exchange proven secure against insider dictionary attacks.仅通过密码认证的三方密钥交换被证明对内部人员字典攻击具有安全性。
ScientificWorldJournal. 2014;2014:802359. doi: 10.1155/2014/802359. Epub 2014 Sep 18.
2
Security analysis and improvement of an anonymous authentication scheme for roaming services.漫游服务匿名认证方案的安全性分析与改进
ScientificWorldJournal. 2014;2014:687879. doi: 10.1155/2014/687879. Epub 2014 Sep 11.

本文引用的文献

1
Password-only authenticated three-party key exchange with provable security in the standard model.在标准模型中具有可证明安全性的仅密码认证三方密钥交换。
ScientificWorldJournal. 2014;2014:825072. doi: 10.1155/2014/825072. Epub 2014 Apr 14.