Yayınlanmış 1 Ocak 2008 | Sürüm v1
Konferans bildirisi Açık

A Password-based Key Establishment Protocol with Symmetric Key Cryptography

  • 1. TUBITAK UEKAE Gebze, Natl Res Inst Elect & Cryptol, Kocaeli, Turkey
  • 2. Bogazici Univ, Elect Elect Engn Dept, Istanbul, Turkey

Açıklama

In 2005, Laih, Ding and Huang proposed a password-based key establishment protocol such that a user and a server can authenticate each other and generate a strong session key by their shared weak password within a symmetric cipher in an insecure channel. In this protocol, a special function which is a combination of a picture function and a distortion function e. g. CAPTCHA, is combined to authenticate the user and protect the password from the dictionary attacks that are major threats for most of the weak password-based protocols. They claim that the proposed protocol is secure against some well known attacks. However Tang and Mitchell show that the protocol suffers from an offline dictionary attack requiring a machine-based search of size 2(23) which takes only about 2.3 hours. So designing such a protocol with providing practical security against offline attack is still an open problem. In this study, we introduce two password-based authenticated key establishment protocols that provide practical security against offline dictionary attacks by only using symmetric key cryptography.

Dosyalar

bib-49a8365f-85a3-4aff-8a3b-49607dd3ce08.txt

Dosyalar (220 Bytes)

Ad Boyut Hepisini indir
md5:ad35b47f4afd846253cac9508d6ff062
220 Bytes Ön İzleme İndir