Faculty of Information Science, Kim Il Sung University, Pyongyang, the Democratic People's Republic of Korea.
PLoS One. 2022 Jul 28;17(7):e0271817. doi: 10.1371/journal.pone.0271817. eCollection 2022.
The authentication key agreement is a scheme that generates a session key for encrypted communication between two participants. In the authentication key agreement, to provide the mutual authentication and the robust session key agreement is one of the important security requirements to enhance the security performance of key agreement. Recently Zhou et al. had proposed the key agreement protocol using pseudo-identifiers, but we found that there were weaknesses in their protocol. We have demonstrated that Zhou et al.'s protocol is vulnerable to replay attack, fails to provide mutual authentication, no key control, re-registration with the original identifier and efficiency in the verification of wrong password. We improved their scheme and proposed an improved authentication key agreement protocol that provides robust mutual authentication and the secure session key agreement. We analyzed its security performance using BAN logic and AVISPA tools and compared computational cost, communication overhead and security properties with other related schemes.
身份验证密钥协商是一种为两个参与者之间的加密通信生成会话密钥的方案。在身份验证密钥协商中,提供相互认证和强大的会话密钥协商是增强密钥协商安全性性能的重要安全要求之一。最近,Zhou 等人提出了使用伪标识符的密钥协商协议,但我们发现他们的协议存在弱点。我们已经证明 Zhou 等人的协议易受重播攻击、无法提供相互认证、无密钥控制、使用原始标识符重新注册以及错误密码验证效率低下。我们改进了他们的方案,并提出了一种改进的身份验证密钥协商协议,该协议提供了强大的相互认证和安全的会话密钥协商。我们使用 BAN 逻辑和 AVISPA 工具分析了其安全性性能,并与其他相关方案比较了计算成本、通信开销和安全属性。