...
首页> 外文期刊>ScientificWorldJournal >Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks
【24h】

Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks

机译:只密码认证的三方密钥交换证明是安全的内幕词典攻击

获取原文
           

摘要

While a number of protocols for password-only authenticated key exchange (PAKE) in the 3-party setting have been proposed, it still remains a challenging task to prove the security of a 3-party PAKE protocol against insider dictionary attacks. To the best of our knowledge, there is no 3-party PAKE protocol that carries a formal proof, or even definition, of security against insider dictionary attacks. In this paper, we present the first 3-party PAKE protocol proven secure against both online and offline dictionary attacks as well as insider and outsider dictionary attacks. Our construct can be viewed as a protocol compiler that transforms any 2-party PAKE protocol into a 3-party PAKE protocol with 2 additional rounds of communication. We also present a simple and intuitive approach of formally modelling dictionary attacks in the password-only 3-party setting, which significantly reduces the complexity of proving the security of 3-party PAKE protocols against dictionary attacks. In addition, we investigate the security of the well-known 3-party PAKE protocol, called GPAKE, due to Abdalla et al. (2005, 2006), and demonstrate that the security of GPAKE against online dictionary attacks depends heavily on the composition of its two building blocks, namely a 2-party PAKE protocol and a 3-party key distribution protocol.
机译:虽然已经提出了许多仅用于3党设置的密码认证密钥交换(PANK)的协议,但它仍然是一个具有挑战性的任务,以证明对Insider字典攻击的3方偷兵协议的安全性仍然是一个具有挑战性的任务。据我们所知,没有3党的偷水协议,带有正式证明,甚至定义,对内幕词典攻击的安全。在本文中,我们介绍了第一个3党的普及验证,以防止在线和离线词典攻击以及内幕和局外人字典攻击。我们的构建体可以被视为协议编译器,将任何2方普及协议转换为3派举行的额外沟通协议。我们还提出了一种简单而直观的方法,即在仅限密码的3年级设置中正式建模字典攻击,这显着降低了证明3党普法协议的安全性对字典攻击的复杂性。此外,由于ABDALLA等人,我们调查了众所周知的3党普法法协议的安全性,称为GPAKE。 (2005,2006),并证明GPAKE对在线词典攻击的安全性大量取决于其两个构件的组成,即2派达议定书协议和3党的关键分配协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号