首页> 美国卫生研究院文献>other >Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks
【2h】

Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks

机译:经验证的仅密码验证的三方密钥交换可抵御内幕字典攻击

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

While a number of protocols for password-only authenticated key exchange (PAKE) in the 3-party setting have been proposed, it still remains a challenging task to prove the security of a 3-party PAKE protocol against insider dictionary attacks. To the best of our knowledge, there is no 3-party PAKE protocol that carries a formal proof, or even definition, of security against insider dictionary attacks. In this paper, we present the first 3-party PAKE protocol proven secure against both online and offline dictionary attacks as well as insider and outsider dictionary attacks. Our construct can be viewed as a protocol compiler that transforms any 2-party PAKE protocol into a 3-party PAKE protocol with 2 additional rounds of communication. We also present a simple and intuitive approach of formally modelling dictionary attacks in the password-only 3-party setting, which significantly reduces the complexity of proving the security of 3-party PAKE protocols against dictionary attacks. In addition, we investigate the security of the well-known 3-party PAKE protocol, called GPAKE, due to Abdalla et al. (2005, 2006), and demonstrate that the security of GPAKE against online dictionary attacks depends heavily on the composition of its two building blocks, namely a 2-party PAKE protocol and a 3-party key distribution protocol.
机译:尽管已经提出了在三方设置中使用多种用于仅口令认证密钥交换(PAKE)的协议,但是证明三方PAKE协议针对内部词典攻击的安全性仍然是一项艰巨的任务。据我们所知,没有3方PAKE协议可以对内幕字典攻击进行安全的正式证明,甚至定义。在本文中,我们介绍了首个经过验证的3方PAKE协议,该协议可抵御在线和离线词典攻击以及内部和外部词典攻击。我们的构造可以看作是协议编译器,可以将任何2方PAKE协议转换为3方PAKE协议,并进行另外2轮通信。我们还提供了一种简单而直观的方法,可以在仅密码的3方设置中对字典攻击进行正式建模,从而大大降低了证明3方PAKE协议针对字典攻击的安全性的复杂性。此外,由于Abdalla等人的缘故,我们研究了称为GPAKE的著名3方PAKE协议的安全性。 (2005,2006),并证明了GPAKE对抗在线字典攻击的安全性在很大程度上取决于其两个构件的组成,即2方PAKE协议和3方密钥分发协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号