首页> 外文期刊>電子情報通信学会技術研究報告 >About Security of Threshold Anonymous Password-Authenticated Key Exchange
【24h】

About Security of Threshold Anonymous Password-Authenticated Key Exchange

机译:关于阈值匿名密码身份验证密钥交换的安全性

获取原文
获取原文并翻译 | 示例
       

摘要

An anonymous password-authenticated key exchange protocol is designed to provide both password-only authentication and client anonymity against a semi-honest server, who honestly follows the protocol. In IN-DOCRYPT2008, Yang and Zhang [24] proposed a new anonymous PAKE (NAPAKE) protocol and its threshold (D-NAPAKE) which they claimed to be secure against insider attacks. In this paper, we first show that the D-NAPAKE protocol [24] is insecure against insider attacks unlike their claim. Specifically, only one legitimate client can freely impersonate any subgroup of clients (the threshold t > 1) to the server. Then, we propose a threshold anonymous PAKE (called, TAP~+) protocol which provides security against insider attacks. Moreover, we prove that the TAP~+ protocol is AKE-secure against active attacks as well as insider attacks under the computational Difne-Hellman problem, and provides client anonymity against a semi-honest server, who honestly follows the protocol. Finally, several discussions are followed: 1) We also show another threshold anonymous PAKE protocol by applying our Rationale to the (non-threshold) anonymous PAKE (VEAP) protocol [21]; and 2) We give the efficiency comparison and security consideration of the TAP~+ protocol.
机译:匿名密码身份验证的密钥交换协议旨在针对半诚实的服务器提供纯密码身份验证和客户端匿名,诚实地遵循该协议。在IN-DOCRYPT2008中,Yang和Zhang [24]提出了一个新的匿名PAKE(NAPAKE)协议及其阈值(D-NAPAKE),他们声称这种协议可以防止内部攻击。在本文中,我们首先表明D-NAPAKE协议[24]不像内部攻击者所声称的那样是不安全的。具体来说,只有一个合法客户端可以将服务器的任何子组(阈值t> 1)自由地模拟到服务器。然后,我们提出了一个阈值匿名PAKE(称为TAP〜+)协议,该协议可提供针对内部攻击的安全性。此外,我们证明TAP〜+协议在计算的Difne-Hellman问题下对主动攻击和内部攻击均具有AKE安全性,并为诚实遵循该协议的半诚实服务器提供了客户端匿名性。最后,进行了以下讨论:1)通过将我们的基本原理应用于(非阈值)匿名PAKE(VEAP)协议,我们还展示了另一个阈值匿名PAKE协议[21]; 2)给出了TAP〜+协议的效率比较和安全性考虑。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号