高效的基于口令的三方密钥交换协议

Efficient Three-Party Password-Based Authenticated Key Exchange Protocol

  • 摘要: 基于口令的三方密钥交换协议,通过一个保存了客户的口令或是关于口令的验证值的可信第三方服务器,实现了两个需要相互通信的客户的身份认证和密钥协商。但由于口令的低熵性,使得现有的很多基于口令的三方密钥交换协议容易遭受字典攻击。在现有协议的基础上,利用对称加密算法和Diffie-Hellman两方密钥交换方法,提出了一个高效的基于口令的三方密钥交换协议。该协议能抵御各种现有的攻击,并提供完美的前向安全性。

     

    Abstract: Three-party password-based authenticated key exchange protocols allow two clients to authenticate each other and establish a shared session key through a trusted server who preserves clients' passwords or verifiers about passwords. However, because of the low entropy of passwords, password-based authenticated key exchange protocols are vulnerable to dictionary attacks. Based on available protocols, a new efficient three-party password-based authenticated key exchange protocol is proposed by combining the symmetric encryption algorithm with the method of two-party key exchange protocol of Diffie-Hellman. Results indicate that and the proposed protocol can resist against various attacks and provide the perfect forward security.

     

/

返回文章
返回