论文部分内容阅读
针对2个具有完美前向机密性的鲁棒电子邮件协议所存在的安全缺陷,分析了2个协议所面临的协议攻击,并得出了相应的改进方案.首先,通过对2个电子邮件协议的分析,提出了相应的中间人攻击方法,其中攻击者在协议的接收阶段通过伪造信息来欺骗通信双方,并使通信双方与其共享错误的会话密钥.由此中间人攻击使得2个电子邮件协议的完美前向机密性得不到保证.其次,通过在2个协议的接收阶段加入相应的签名信息,提出了对2个协议的改进方案,以确保改进协议能够克服中间人攻击并且提供协议的完美前向机密性.此外,经改进的协议仍然能够保持原协议的所有优点.
Aiming at the security flaws of the two robust e-mail protocols with perfect forward secrecy, the protocol attacks faced by the two protocols are analyzed and the corresponding improvements are obtained.Firstly, by analyzing the two e-mail protocols , A corresponding man-in-the-middle attack method is proposed, in which the attacker deceives the two parties by falsifying the information during the receiving phase of the protocol, and both parties of the communication share the wrong session key with the attacker, so that the man-in-the-middle attack makes the two e-mail protocols Perfect forward confidentiality can not be guaranteed.Secondly, by adding corresponding signature information in the receiving phase of the two protocols, an improved scheme of two protocols is proposed to ensure that the improved protocol can overcome the man-in-the-middle attack and provide the perfect protocol To the confidentiality.In addition, the improved agreement still can maintain all the advantages of the original agreement.