首页> 外文会议>International conference on networks communications >Cryptanalysis Of Lo et al.'s Password Based Authentication Scheme
【24h】

Cryptanalysis Of Lo et al.'s Password Based Authentication Scheme

机译:Lo等人的基于密码的身份验证方案的密码分析

获取原文

摘要

A key exchange protocol allows more than two parties to communicate over the insecure channel to establish common shared secret key called session key. Due to the significance of this notion to establish secure communication among parties, in literature there have been numerous approach have been proposed and analyzed based on their merits and de-merits. Recently, Lo et al. proposed a 3-party Password based Authenticated Key Exchange protocol in which two or more users equipped with pre-shared secrets to the server and can able to generate the session key with the help of the server. They claimed that their approach is resist against any known attacks. However, we observe that their protocol is not secure against against off-line password guessing attack, long term secret compromise attack as well as compromise of previous session can lead to compromise all involving users for future communication. Therefore, in this this paper first we have analyzed these attacks and suggest the improve scheme that overcomes these attacks.
机译:密钥交换协议允许两个以上的参与者在不安全的通道上进行通信,以建立称为会话密钥的公共共享秘密密钥。由于该概念对于建立各方之间的安全通信的重要性,在文献中,已经根据其优缺点提出了许多方法并进行了分析。最近,Lo等。提出了一种基于三方密码的身份验证密钥交换协议,该协议中两个或两个以上具有预共享服务器机密的用户,并能够在服务器的帮助下生成会话密钥。他们声称他们的方法是抵抗任何已知的攻击。但是,我们观察到他们的协议不能抵御离线密码猜测攻击,长期的秘密泄露攻击以及先前会话的泄露,从而可能会损害所有涉及用户的通信。因此,在本文中,我们首先分析了这些攻击,并提出了克服这些攻击的改进方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号