Cryptanalysis on Shim’s tripartite authenticated key agreement protocol from Weil pairing
全文
(2) Int. Computer Symposium, Dec. 15-17, 2004, Taipei, Taiwan.. 4. Cryptanalysis on Shim’s protocol In this section, we present two kinds of attacks on Shim’s scheme including the insider attack and the key-compromise impersonation attack.. 4.1. The insider attack In a tripartite key agreement protocol, the insider attack [3] means that some one of the entities tries to impersonate any other entity. For instance, B is an insider attacker who might try to impersonate C (to fool A) that he and C have participated in a key agreement protocol at the same time, while in fact C does not. If the insider attack is successfully launched in Shim’s protocol, it could have damaging consequences: for example, if C acts as an on-line escrow agent or a referee. Assumptions (i) A, B and C: Legal entities appear in a tripartite key agreement protocol. (ii) CertA, CertB and CertC: The certificates of A, B and C, respectively, have been certified by a trusted CA. (iii) B: The insider attacker wants to impersonate C to A and has the CertC beforehand. (iv) C: The insider entity is unknown to the communication round. Based on the above assumptions the insider attacker B, then, initiates a key agreement protocol, and also plays another role C' (masquerades as C to fool A). Therefore, A mistakenly accepts C' as the real C. Insider attack algorithm (I1) B: TC' = z' · YC = z' · (cP). (I2) B → A, C': {TB, CertB} (I3) C' → A, B : {TC', CertC}. trusted CA. (iii) E: The outsider attacker wants to impersonate both of A and C and communicate with B. Note that E now owns the messages {b, TB, CertB} and has got the CertA and CertC beforehand. (iv) A, C: The insider entities are unknown to this communication round. The outsider attacker E pretends to be A and C, indicated as A' and C', respectively. E can initiate a key agreement protocol among the three entities A', B and C' and impersonate both the roles of A and C to cheat B. Therefore, B mistakenly believes that A' is the real A and C' is the real C. Key-compromise impersonation algorithm (K1) E: TA' = u·P and TC' = w·P (K2) E → B: {TA', CertA},{TC', CertC} (K3) B → A', C': {TB, CertB} (K4) Computes KA' = KB = KC' = eˆ( P, P)b y u wˆ(e P, P) (K5) K = kdf ( K A' || A'|| B|| C' ) = kdf ( KB||A' || B|| C' ) = abc. kdf (K C '|| A'|| B|| C' ). 5. Conclusion Shim [1] proposed an improved tripartite authenticated key agreement protocol based on Weil pairing to resist the man-in-the-middle attack. This letter shows that Shim’s tripartite authenticated key agreement protocol is still insecure against some attacks including the insider attack and the keycompromise impersonation. These attacks are due to that the partial messages (such as the public ephemeral key TA, TB and TC) are not authenticated. From the proposed cryptanalysis, Shim’s protocol seems not satisfying some basic security requirements.. References. (I4) A → B, C': {TA, CertA} abc. (I5) Computes KA = KB = KC'= eˆ( P , P)abcxyz'eˆ(P ,P ) (I6) K= kdf ( K A || A || B || C' )= kdf ( K B || A || B || C' )= kdf. ( K ' || A || B || C' ) C. 4.2. Key-compromise impersonation attack An outsider attacker E, who has compromised B’s static private key b, can also impersonate the other entities to B. The details are illustrated as below. Assumptions (i) A, B and C: Legal entities appear n a tripartite key agreement protocol. (ii) CertA, CertB and CertC: The certificates of A, B and C, respectively, have been certified by a. 1035. [1] K. Shim, “Efficient one-round tripartite authenticated key agreement protocol from Weil pairing,” Electronics Letters, Vol. 39, no. 2, pp.208209, January, 2003. [2] A. Joux, “A one-round protocol for tripartite Diffie-Hellman,” Proceedings of the 4th International Algorithmic Number Theory Symposium (ANTS-IV), LNCS 1838, pp.385-394, July, 2000. [3] S.S. Al-Riyami, and K.G. Paterson, “Tripartite authenticated key agreement protocol from pairings,” IMA Conference on Cryptography and Coding 2003, LNCS 2898, pp.332-359, December, 2003..
(3)
相關文件
4-7 The photocopy of the letter of agreement between Business Incubation Center of Feng Chia University and the applied company over the operations and cultivations.. 4-8
4-7 The photocopy of the letter of agreement between Business Incubation Center of Feng Chia University and the applied company over the operations and cultivations.. 4-8
Employer and employee’s mutual agreement certificate for continuous hiring: to be filled up by the Employer (If Letter of Consent is not enough, please follow the specific form to
To proceed, we construct a t-motive M S for this purpose, so that it has the GP property and its “periods”Ψ S (θ) from rigid analytic trivialization generate also the field K S ,
We need a whole-school approach, together with joint efforts made at different levels, ranging from the system to the school organisation, the school curriculum (including
The case where all the ρ s are equal to identity shows that this is not true in general (in this case the irreducible representations are lines, and we have an infinity of ways
Continue to serve as statements of curriculum intentions setting out more precisely student achievement as a result of the curriculum.
In implementing the key tasks, schools should build on past experiences and strengthen the development of the key tasks in line with the stage of the curriculum reform, through