首页> 外文期刊>The Computer journal >A Verifier-Based Password-Authenticated Key Exchange Using Tamper-Proof Hardware
【24h】

A Verifier-Based Password-Authenticated Key Exchange Using Tamper-Proof Hardware

机译:基于验证者的密码认证密钥交换,使用防篡改硬件

获取原文
获取原文并翻译 | 示例

摘要

Password-based authenticated key exchange (PAKE) allows two parties to compute a common secret key. PAKE offers the advantage of allowing two parties to pre-share only a password. However, when it is executed in a client-server environment, server corruption can expose the clients' passwords. To be resilient against server compromises, verifier-based authenticated key exchange (VPAKE) is proposed, as an augmented version of PAKE. Thus far, there are two known major VPAKE constructions formally proven secure. However, both involve strong assumptions, such as random oracles. In this paper, we propose a simple and efficient VPAKE using tamper-proof hardware without random oracles to support resilient infrastructures. In particular, we transform Katz-Vaikuntanathan one-round PAKE into two-round VPAKE so as to instill resilience to server compromises. We provide a formal definition of VPAKE using tamper-proof hardware and security proof without random oracles. Finally, we provide a performance analysis and comparisons to previous VPAKE and PAKE protocols. Our transformation supports an efficient VPAKE protocol with six group element communications when the underlying Katz-Vaikuntanathan PAKE is instantiated by Cramer-Shoup ciphertext following the proposal by Benhamouda et al.
机译:基于密码的经过密码验证密钥交换(PANK)允许两方计算共同的密钥。培育提供了允许两方只预先分享密码的优势。但是,当它在客户端 - 服务器环境中执行时,服务器损坏可能会暴露客户端的密码。为了对服务器妥协进行弹性,提出了基于验证者的经过认证密钥交换(VPake),作为普及的增强版本。到目前为止,有两种已知的主要vPake结构正式证明安全。然而,两者都涉及强烈的假设,例如随机oracles。在本文中,我们使用无随机奥克斯的防篡改硬件提出了一种简单而有效的VPake,以支持弹性基础设施。特别是,我们将katz-vaikuntanathan一键入双轮vpake转换为两轮vpake,以灌输到服务器妥协的弹性。我们使用篡改硬件和安全证明提供了没有随机oracles的安全证明的正式定义。最后,我们为以前的vPake和培育协议提供了绩效分析和比较。当Benhamouda等人的提案后,我们的转换支持具有六个组元素通信的六组元素通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号