...
首页> 外文期刊>International Journal of Information Security >User-mediated authentication protocols and unforgeability in key collision
【24h】

User-mediated authentication protocols and unforgeability in key collision

机译:用户介导的身份验证协议和关键碰撞中的不可识别性

获取原文
获取原文并翻译 | 示例

摘要

User interaction constitutes a largely unexplored field in protocol analysis, even in instances where the user takes an active role as a trusted third party, such as in the Internet of Things (IoT) device initialization protocols. Initializing the formal modeling of 3-party authentication protocols where one party is a physical user, this research introduces the 3-party possession user-mediated authentication (3-PUMA) model. The 3-PUMA model addresses active user participation in a protocol which is designed to authenticate possession of a fixed data string-such as in IoT device commissioning. Using the 3-PUMA model, we provide a computational analysis of the ISO/IEC 9798-6:2010 standard's Mechanism 7a authentication protocol which includes a user interface and interaction as well as a device-to-device channel. Furthermore, we introduce existential unforgeability under key collision attacks (EUF-KCA) and provide a corresponding security experiment. We show that the security of ISO/IEC 9798-6:2010 Mechanism 7a relies upon EUF-KCA MAC security. Since it is unknown whether any standardized MAC algorithm achieves EUF-KCA security, this research demonstrates a potential vulnerability in the standard.
机译:用户交互在协议分析中构成了一个很大程度上的未开发的字段,即使在用户作为可信第三方中的活动角色的情况下,例如在Internet(IoT)设备初始化协议中。初始化3-一方是物理用户的3方认证协议的正式建模,本研究介绍了3党占有用户介导的认证(3-PUMA)模型。 3-PUMA模型解决了主动用户参与的协议,该协议旨在验证固定数据字符串的拥有 - 例如在IoT设备调试中。使用3-PUMA模型,我们提供了ISO / IEC 9798-6:2010标准的机制7A认证协议的计算分析,包括用户界面和交互以及设备到设备通道。此外,我们在关键碰撞攻击(EUF-KCA)下引入存在的不可识别性,并提供相应的安全实验。我们表明ISO / IEC 9798-6:2010机制7A的安全性依赖于EUF-KCA MAC安全性。由于尚不清楚是否有任何标准化的MAC算法达到EUF-KCA安全性,因此该研究表明了标准中的潜在漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号