新型三方口令认证密钥协商协议的安全性分析与改进  

Analysis and improvement on new three-party password-based authenticated key agreement protocol

在线阅读下载全文

作  者:李丽琳[1] 刘柱文[1] 

机构地区:[1]永州职业技术学院计算机系,湖南永州425000

出  处:《计算机应用》2011年第8期2192-2195,共4页journal of Computer Applications

摘  要:口令认证密钥协商(PAKA)是认证密钥协商(AKA)中的重要分支之一。研究了一种新型三方口令认证密钥协商——3REKA的安全性,发现如果参与双方的验证值丢失,将导致严重的中间人攻击,这一攻击的结果是敌手可以与参与者各自建立独立的会话密钥。描述了这一攻击,并对原协议进行了改进,提出了I-3REKA协议。安全性和性能分析表明,所提出的协议以较低的计算量实现了参与双方的安全通信。Password-based Authenticated Key Agreement(PAKA) is an important research point of Authenticated Key Agreement(AKA) protocols.The authors analyzed a new protocol named three-party Round Efficient Key Agreement(3REKA) and found that if the verification values were stolen or lost,the adversary could initiate the man-in-the-middle attack.The result of this attack was serious: the adversary could establish two session keys with two different participants.This attack was described and an improved protocol called Improved 3REKA(I-3REKA) was proposed in this paper.The analysis on the security and performance show that the proposed protocol can realize secure communication with lower computational cost.

关 键 词:信息安全 密钥协商 口令 中间人攻击 

分 类 号:TP309.7[自动化与计算机技术—计算机系统结构] TP393.08[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象