首页> 外文期刊>Information Fusion >Cryptanalysis of a remote user authentication scheme for mobile client-server environment based on ECC
【24h】

Cryptanalysis of a remote user authentication scheme for mobile client-server environment based on ECC

机译:基于ECC的移动客户端-服务器环境远程用户认证方案的密码学分析

获取原文
获取原文并翻译 | 示例
           

摘要

Understanding security failures of cryptographic protocols is the key to both patching existing protocols and designing future schemes. The design of secure remote user authentication schemes based on elliptic curve crypto-graphy (ECC) for mobile applications is still quite a challenging problem, though many schemes have been published lately. In this paper, we analyze an efficient ID-based scheme for mobile client-server environment without the MapToPoint function introduced by He et al. in 2012. This proposal attempts to overcome many of the well known security and efficiency shortcomings of previous schemes, and it also carries a claimed proof of security in the random oracle model. However, notwithstanding its formal security arguments, we show that He et al.'s protocol even cannot attain the basic goal of mutual authentication by demonstrating its vulnerabilities to reflection attack and parallel session attack. Besides these two security vulnerabilities, their scheme also suffers from some practical pitfalls such as user anonymity violation and clock synchronization problem. In addition, we carry out an investigation into their security proof and propose some changes to the scheme so that it can achieve at least its basic security goal, in the hope that similar mistakes are no longer made in the future.
机译:了解加密协议的安全性失败是修补现有协议和设计未来方案的关键。尽管最近已经发布了许多方案,但基于椭圆曲线密码学(ECC)的安全远程用户身份验证方案的设计仍然是一个充满挑战的问题。在本文中,我们分析了一种有效的基于ID的移动客户端-服务器环境方案,该方案没有He等人介绍的MapToPoint函数。这项提议在2012年提出。该提议试图克服先前方案的许多众所周知的安全性和效率性缺陷,并且在随机预言模型中还带有声称的安全性证明。但是,尽管有形式上的安全性争论,但我们证明He等人的协议通过展示其对反射攻击和并行会话攻击的脆弱性,甚至无法实现相互认证的基本目标。除了这两个安全漏洞之外,它们的方案还遭受一些实际的陷阱,例如用户匿名违规和时钟同步问题。另外,我们对它们的安全性证明进行了调查,并提出了对该方案的一些更改,以使其至少可以实现其基本安全性目标,希望以后不再犯类似的错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号