首页> 外文会议>International conference on networks communications >Cryptanalysis Of Lo et al.'s Password Based Authentication Scheme
【24h】

Cryptanalysis Of Lo et al.'s Password Based Authentication Scheme

机译:Lo等人的密码分析。基于密码的身份验证方案

获取原文

摘要

A key exchange protocol allows more than two parties to communicate over the insecure channel to establish common shared secret key called session key. Due to the significance of this notion to establish secure communication among parties, in literature there have been numerous approach have been proposed and analyzed based on their merits and de-merits. Recently, Lo et al. proposed a 3-party Password based Authenticated Key Exchange protocol in which two or more users equipped with pre-shared secrets to the server and can able to generate the session key with the help of the server. They claimed that their approach is resist against any known attacks. However, we observe that their protocol is not secure against against off-line password guessing attack, long term secret compromise attack as well as compromise of previous session can lead to compromise all involving users for future communication. Therefore, in this this paper first we have analyzed these attacks and suggest the improve scheme that overcomes these attacks.
机译:密钥交换协议允许超过两方通过不安全的通道进行通信,以建立名为会话密钥的公共共享密钥。由于这一概念在各方之间建立了安全沟通,在文献中,已经提出了许多方法,并根据其优点和解放度进行了分析。最近,Lo等人。提出了一种基于3党的密码经过身份验证的密钥交换协议,其中两个或多个配备了服务器的预共享秘密的用户,并且可以在服务器的帮助下生成会话密钥。他们声称他们的方法是抵抗任何已知的攻击。然而,我们观察到他们的协议无法防止违法的密码猜测攻击,长期秘密妥协攻击以及前一届会话的妥协可以导致所有涉及用户涉及未来通信的危害。因此,在本文中,首先我们分析了这些攻击,并提出了克服这些攻击的改进方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号