Logo image
The Research on Password-Based Authenticated Key Exchange Secure Against Stolen-Secret Attacks
Thesis

The Research on Password-Based Authenticated Key Exchange Secure Against Stolen-Secret Attacks

Po-Hung Chen
Masters, 國立清華大學, 資訊系統與應用研究所
2004

Abstract

雙向身份認證協定 可證明之安全性 祕密金鑰竊取攻擊 authentication key exchange provable security stolen secret-key attack
Entity authentication is one of the most important security functions. It is necessary for verifying the identities of the communicating parties when they initiate their connection. This function is usually provided with a key establishment scheme such as key agreement between the parties. For user authentication, three kinds of approaches exist: knowledge-based authentication, token-based authentication, and biometric authentication. Among them, the knowledge-based scheme is for human memory. Actually, it is the most widely-used method due to such advantages as simplicity, convenience, adaptability, mobility, and less hardware requirement. It requires users only to remember their knowledge such as a password or PIN (Personal Identification Number). Therefore, users are allowed to move conveniently without carrying hardware tokens. However, a complex problem with this password-only authentication is that a human-memorable password has low entropy so that it could be vulnerable to malicious guessing attacks. The problem becomes much more critical in an open distributed environment. Moreover, password file protection is another problem that makes password authentication more unreliable. A cryptographic protocol based on public-key cryptography is the most promising solution to this problem. We define the term Stolen Secret Key Attack for authentication key exchange (AKE) protocol - when the password of a client is compromised by the adversary; she not only can impersonate the client to login a server, but also masquerade the server to fool the client. All password based AKE protocols suffer from this attack. To solve this problem, we propose a new password-based AKE protocol using RSA and show that it is secure against the stolen secret-key attack. An efficient implementation of RSA will be given at the end of the paper.

Metrics

1 Record Views

Details

Logo image