首页> 外文会议>Applied cryptography and network security. >Security Analysis of a Multi-factor Authenticated Key Exchange Protocol
【24h】

Security Analysis of a Multi-factor Authenticated Key Exchange Protocol

机译:多因素认证密钥交换协议的安全性分析

获取原文
获取原文并翻译 | 示例

摘要

This paper shows several security weaknesses of a Multi-Factor Authenticated Key Exchange (MK-AKE) protocol, proposed by Pointcheval and Zimmer at ACNS'08. The Pointcheval-Zimmer scheme was designed to combine three authentication factors in one system, including a password, a secure token (that stores a private key) and biometrics. In a formal model, Pointcheval and Zimmer formally proved that an attacker had to break all three factors to win. However, the formal model only considers the threat that an attacker may impersonate the client; it however does not discuss what will happen if the attacker impersonates the server. We fill the gap by analyzing the case of the server impersonation, which is a realistic threat in practice. We assume that an attacker has already compromised the password, and we then present two further attacks: in the first attack, an attacker is able to steal a fresh biometric sample from the victim without being noticed; in the second attack, he can discover the victim's private key based on the Chinese Remainder theorem. Both attacks have been experimentally verified. In summary, an attacker actually only needs to compromise a single password factor in order to break the entire system. We also discuss the deficiencies in the Pointcheval-Zimmer formal model and countermeasures to our attacks.
机译:本文显示了Pointcheval和Zimmer在ACNS'08上提出的多重身份验证密钥交换(MK-AKE)协议的一些安全漏洞。 Pointcheval-Zimmer方案旨在在一个系统中结合三个认证因素,包括密码,安全令牌(用于存储私钥)和生物识别。在正式模型中,Pointcheval和Zimmer正式证明了攻击者必须打破所有三个因素才能获胜。但是,正式模型仅考虑了攻击者可能冒充客户的威胁。但是,它没有讨论如果攻击者冒充服务器会发生什么情况。我们通过分析服务器模拟的情况来填补空白,这在实践中是现实的威胁。我们假定攻击者已经破坏了密码,然后我们提出了另外两种攻击:在第一次攻击中,攻击者可以从受害者那里窃取新鲜的生物特征样本而不会被发现;在第二次攻击中,他可以根据中国剩余定理发现受害者的私钥。两种攻击都已通过实验验证。总而言之,攻击者实际上只需要破坏单个密码因素即可破坏整个系统。我们还讨论了Pointcheval-Zimmer正式模型中的缺陷以及我们的攻击对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号