首页> 外文期刊>IEEE transactions on dependable and secure computing >A Key for John Doe: Modeling and Designing Anonymous Password-Authenticated Key Exchange Protocols
【24h】

A Key for John Doe: Modeling and Designing Anonymous Password-Authenticated Key Exchange Protocols

机译:John Doe的一个关键:建模和设计匿名密码验证的密钥交换协议

获取原文
获取原文并翻译 | 示例
       

摘要

Anonymous Password-Authenticated Key Exchange (APAKE) can be seen as the hybrid offspring of standard key exchange and anonymous password authentication protocols. APAKE allows a client holding a low-entropy password to establish a session key with a server, provided that the client's password is in the server's set. Moreover, no information about the password input by the client or the set of valid passwords held by the server should leak to the other party-beyond whether the client's password lies or not in the server's password database. To the best of our knowledge, all APAKE proposals to date either assume client storage or force the client to remember the index assigned to its password in the server's database. Furthermore, earlier works either provide only informal definitions or fail in some sense to properly model the primitive. In this paper, we provide a formal security model for APAKE, capturing security and anonymity provisions for both clients and servers. In addition, we present two APAKE protocols that only require clients to remember a password and that attain our sought key secrecy and anonymity guarantees. Our first protocol leverages oblivious pseudo-random functions, while the second one builds upon a special type of identity-based encryption scheme.
机译:匿名密码验证的密钥交换(APAKE)可以被视为标准密钥交换和匿名密码认证协议的混合后代。 ePake允许持有低熵密码的客户端与服务器建立会话密钥,只要客户端的密码位于服务器集中。此外,没有关于客户端输入的密码的信息或服务器保持的一组有效密码应该泄漏到另一方 - 超出客户端的密码是否在于或不在服务器的密码数据库中。据我们所知,迄今为止,所有APAKE提案都假设客户端存储或强制客户端将分配给服务器数据库中的密码的索引。此外,早期的工作要么只提供非正式的定义,要么在某种意义中取得了不正确的模拟原始的。在本文中,我们为客户端和服务器拍摄,捕获安全性和匿名规定提供了正式的安全模型。此外,我们还提出了两个待遇协议,只需要客户来记住密码,并达到我们寻求的关键保密和匿名保证。我们的第一个协议利用了令人沮丧的伪随机函数,而第二个协议基于特殊类型的基于身份的加密方案构建。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号