A Security Patch for a Three-Party Key Exchange Protocol

来源 :Wuhan University Journal of Natural Sciences | 被引量 : 0次 | 上传用户:xilotola
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The CLC protocol (proposed by Tzung-Her Chen, Wei-Bin Lee and Hsing-Bai Chen, CLC, for short) is a new three-party password-authenticated key exchange (3PAKE) protocol. This CLC protocol provides a superior round efficiency (only three rounds), and its resources required for computation are relatively few. However, we find that the leakage of values V Aand VB in the CLC protocol will make a man-in-the-middle attack feasible in practice, where V Aand VB are the authentication information chosen by the server for the participants A and B . In this paper, we describe our attack on the CLC protocol and further present a modified 3PAKE protocol, which is essentially an improved CLC protocol. Our protocol can resist attacks available, including man-in-the-middle attack we mount on the initial CLC protocol. Meanwhile, we allow that the participants choose their own passwords by themselves, thus avoiding the danger that the server is controlled in the initialization phase. Also, the computational cost of our protocol is lower than that of the CLC protocol. The CLC protocol (proposed by Tzung-Her Chen, Wei-Bin Lee and Hsing-Bai Chen, CLC, for short) is a new three-party password-authenticated key exchange (3PAKE) protocol. This CLC protocol provides a superior round efficiency (only three rounds), and its resources required for computation are relatively few. However, we find that the leakage of values ​​V Aand VB in the CLC protocol will make a man-in-the-middle attack feasible in practice, where V Aand VB are the authentication information chosen by the server for the participants A and B. In this paper, we describe our attack on the CLC protocol and further present a modified 3 PAKE protocol, which is essentially an improved CLC protocol. Our protocol can resist attacks available , including man-in-the-middle attack we mount on the initial CLC protocol. Meanwhile, we allow that the participants choose their own passwords by themselves, thus avoiding the danger that the server is controlled in the initialization phase. Also, the computatio nal cost of our protocol is lower than that of the CLC protocol.
其他文献
不少人喜欢玩腾讯微博,有事没事都会写点什么通过微博发送出去,微博内容不仅能被众多“听众”看到,而且微博动态还会实时显示在QQ好友QQ空间的个人中心主页中(如图1).只要是
虽然现在主流的网页浏览器,都有网页广告过滤的相关功能.但是很多时候我们却发现,这些功能的广告过滤并不完善.那么通过什么方法或软件可以,进一步完善广告过滤的效果呢,其实
没有一款安全防护软件是万能的,一些术业有专攻的小软件往往能够弥补那些所谓全方位系统防护方案中的不足,在防患于未然及危机处理方面达到更好的效果.比如,当系统已被病毒破
今天你“围脖”了吗?此言是时下最流行的网络用语,如今,大家都在新浪微博上以各种给力的文字以及图片和视频在不断地编织着自己的“围脖”,而新浪微博APP的开放,给用户带来了
本文通过对类固醇激素多残留测定的研究探讨,优化并简化了提取和净化过程,建立了用高效液相色谱/离子阱串联质谱( HPLC一MS/MS)测定动物肌肉中群勃龙、勃地酮和黄体酮多残留的
在Word中阅读超长文档比较麻烦,要查找特定的内容需要不断地滚动鼠标或拖动滚动条.为了解决这一问题,Word 2010新增了导航窗格:运行Word 2010,单击视图按钮,勾选导航窗格,即
近年来,伴随着我国经济持续高速增长,房价也一路走高,并成为人们日益关注的热点问题。本文认为造成我国房价节节攀升的原因在于:需求拉动,供给不足并且供给结构不合理以及开
我们知道,WlnRAR是一款最常用的压缩软件,同时也是一款功能强劲的加密工具。将重要的文件加密压缩,可以有效保护其安全。不过在一般情况下,我们几乎都是为整个压缩包设置单一的密码,其后果是旦密码泄露,整个压缩包中的文件就无秘密可言了。实际上,我们完全可以为压缩包中的每个文件分别设置不同的密码,这样即使泄露单个密码,对加密包整体危害并不大。
本文介绍了油脂样品经过水蒸气蒸馏,吹扫捕集(P&T)前处理后,进行GC一MS定性分析油脂中的醛、酮等羰基化合物。文献中未见测定油脂中醛、酮类化合物,特别是丙烯醛的方法。
现在很多童鞋都在使用网易邮箱,但是在实际使用中的一些小技巧可以让你的邮箱使用起来更给力.如果你不知道的话,那么咱们一起来共同学习一下吧!