期刊文献+

一个前向安全的基于口令认证的三方密钥交换协议(英文) 被引量:8

Three-Party Password-Based Authenticated Key Exchange with Forward-Security
下载PDF
导出
摘要 目前,文献中提出的基于口令认证的密钥交换协议,很多都是针对两方的情形设计的,即通信双方为客户与服务器,它们通过一个预先共享的口令来进行认证的密钥交换.随着现代通信环境的快速变化,需要能为任意客户间构建一个端到端的安全信道,这种应用的情形与那些文献中所考虑的有很大区别.针对这种情形,文中提出了一个可证前向安全的基于口令认证的三方密钥交换协议,使通信双方在认证服务器的帮助下能相互进行认证并建立一个会话密钥.与前人提出的基于口令认证的三方密钥交换协议相比,该协议在计算代价和通信代价上都较有效,因而更适用于资源受限的环境.此协议的安全性是在口令型的选择基Gap Diffie-Hellman问题难解的假设前提下在随机谕示模型下证明的. Most password-authenticated key exchange schemes in the literature provide an authenticated key exchange between a client and a server based on a pre-shared password. With a rapid change in modern communication environments, it is necessary to construct a secure end-to- end channel between clients, which is a quite different paradigm from the existing ones. The authors propose a provably forward-secure three-party password-based authenticated key exchange protocol in which two communication entities can authenticate each other and establish a session key through the assistance of an authentication server. The proposed protocol is efficient both in computational cost and in communication cost when compared with previous solutions and thus attractive in resources-constrained environment. The security of the proposed scheme has been proven in the random oracle model under the password chosen-basis Gap Diffie-Hellman assumption.
出处 《计算机学报》 EI CSCD 北大核心 2007年第10期1833-1841,共9页 Chinese Journal of Computers
基金 国家自然科学基金项目(60473021)资助.
关键词 口令 前向安全 三方 带认证的密钥交换 随机谕示 password forward-secure three-party authenticated key exchange random oracle
  • 相关文献

参考文献23

  • 1Bellovin S M,Merritt M.Encrypted key exchange:Password-based protocols secure against dictionary attacks//Proceedings of the 1992 IEEE Computer Society Symposium on Research in security and Privacy.Oakland,California,USA,1992:72-84.
  • 2Boyko V,MacKenzie P,Patel S.Provably secure password authenticated key exchange using diffie-hellman//Proceedings of the 2000 Advances in cryptology (EUROCRYPT'2000).Bruges,Belgium,2000:156-171.
  • 3Bellare M,Pointcheval D,Rogaway P.Authenticated key exchange secure against dictionary attacks//Proceedings of the 2000 Advances in Cryptology (EUROCRYPT' 2000).Bruges,Belgium,2000:139-155.
  • 4Boyko V,MacKenzie P D,Patel S.Provably secure password-authenticated key exchange using Diffie-Hellman//Proceedings of the 2000 Advances in Cryptology(EUROCRYPT'2000).Bruges,Belgium,2000:156-171.
  • 5Bresson E,Chevassut O,Pointcheval D.New security results on encrypted key exchange//Proceedings of the 7th International Workshop on Theory and Practice in Public Key Cryptography(PKC'2004).Singapore,2004:145-158.
  • 6Gennaro R,Lindell Y.A framework for password-based authenticated key exchange//Proceedings of the 2003 Advances in Cryptology (EUROCRYPT' 2003).Warsaw,Poland,2003:524-543.
  • 7Goldreich O,Lindell Y.Session-key generation using human passwords only//Proceedings of the 2001 Advances in Cryptology(CRYPTO'2001).Santa Barbara,California,USA,2001:408-432.
  • 8Abdalla M,Pointcheval D.Simple password-based encrypted key exchange protocols//Proceedings of the 2005 Topics in Cryptology (CT-RSA' 2005).San Francisco,California,USA,2005:191-208.
  • 9Abdalla M,Chevassut O,Pointcheval D.One-time verifierbased encrypted key exchange//Proceedings of the 8th Inter-national Workshop on Theory and Practice in Public Key (PKC'2005).Les Diablerets,Switzerland,2005:4-7-64.
  • 10Gong L,Lomas M,Needham R,Saltzer J.Protecting poorly chosen secrets from guessing attacks.IEEE Journal of Selected Areas Communications,1993,11(5):648-656.

同被引文献65

引证文献8

二级引证文献33

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部