作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (19): 21-24,29. doi: 10.3969/j.issn.1000-3428.2012.19.005

• 专栏 • 上一篇    下一篇

强安全性的三方口令认证密钥交换协议

陈 勇,王立斌,龚 征   

  1. (华南师范大学计算机学院,广州 510631)
  • 收稿日期:2011-12-07 出版日期:2012-10-05 发布日期:2012-09-29
  • 作者简介:陈 勇(1986-),男,硕士,主研方向:密码学,网络安全;王立斌、龚 征,副教授、博士
  • 基金资助:

    国家自然科学基金资助项目“轻量级分组密码算法研究”(61100201);广东高校优秀青年创新人才培养计划基金资助项目(LYM 11053)

Three-party Password-based Authenticated Key Exchange Protocol with Stronger Security

CHEN Yong, WANG Li-bin, GONG Zheng   

  1. (School of Computer, South China Normal University, Guangzhou 510631, China)
  • Received:2011-12-07 Online:2012-10-05 Published:2012-09-29

摘要:

基于可证明安全的AugPAKE协议,提出一种具有强安全性的三方口令认证密钥交换(3PAKE)协议,协议中避免使用服务器的公钥进行认证,以保证执行效率。安全性分析结果表明,该协议可抵抗字典攻击、服务器泄露攻击等已知攻击,并具有对服务器的密钥保密性以及前向安全性。在随机预言模型下,基于DDH、SDH假设证明了该协议的安全性。

关键词: 口令认证, 密钥交换, 字典攻击, 三方口令认证密钥交换, 随机预言模型

Abstract:

Based on the protocol AugPAKE which has been proven security, this paper proposes a strong security Three-party Password-based Authenticated Key Exchange(3PAKE) protocol, which avoids using the server’s public key to authenticate, and ensures the efficiency. It is proved to be secure against dictionary attacks, server leaked attacks and kinds of known attacks, and also applies key privacy to the server and forward security. The security of the protocol are proved based on Decisional Diffie-Hellman(DDH) problem and Strong Diffie-Hellman(SDH) problem in random oracle model.

Key words: password authentication, key exchange, dictionary attack, Three-party Password-based Authenticated Key Exchange(3PAKE), random oracle model

中图分类号: