首页> 外文期刊>International Journal of Computer Systems Science & Engineering >EV-C2C-PAKE: An improved client-to-client password-authenticated key exchange protocol
【24h】

EV-C2C-PAKE: An improved client-to-client password-authenticated key exchange protocol

机译:EV-C2C-PAKE:改进的客户端到客户端密码验证的密钥交换协议

获取原文
获取原文并翻译 | 示例
           

摘要

With rapid changes in the modern communication environment such as ad hoc networks and ubiquitous computing, it is necessary to construct a secure end-to-end channel between clients. In the last few years, researchers have extensively studied the password-authenticated key exchange (PAKE) in the three-party setting. The fundamental security goal of PAKE is security against dictionary attacks. The protocols for verifier-based PAKE are additionally required to be secure against server compromise. In this paper we propose an efficient verifier-based C2C-PAKE (called EV-C2C-PAKE) protocol resilient to server compromise. The new protocol resists dictionary attacks mounted by either passive or active network intruders, allowing, in principle, even weak password phrases to be used safely. It also offers perfect forward secrecy, which protects past sessions and passwords against future compromises. Finally, user passwords are stored in a form that is not plaintext-equivalent to the password itself, so an attacker who captures the password database cannot use it directly to compromise security and gain immediate access to the host. Furthermore, the authentication server can't get any information for the session key between the two users and the mutual authentication will carry through between the server and the two users.
机译:随着诸如ad hoc网络和无处不在的计算等现代通信环境的迅速变化,有必要在客户端之间构建安全的端到端通道。在过去的几年中,研究人员广泛地研究了在三方环境中进行密码验证的密钥交换(PAKE)。 PAKE的基本安全性目标是针对字典攻击的安全性。此外,还需要针对基于验证者的PAKE的协议,以防服务器受到损害。在本文中,我们提出了一种有效的基于验证程序的C2C-PAKE(称为EV-C2C-PAKE)协议,可以对服务器的攻击进行恢复。新协议可抵抗被动或主动网络入侵者发起的字典攻击,原则上甚至可以安全地使用弱密码短语。它还提供了完美的前向保密性,可以保护过去的会话和密码,以免将来受到威胁。最后,用户密码的存储格式与密码本身不是明文等效的,因此,捕获密码数据库的攻击者无法直接使用它来危及安全性并立即访问主机。此外,身份验证服务器无法获取两个用户之间会话密钥的任何信息,并且相互验证将在服务器和两个用户之间进行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号