节点文献
认证密钥协商协议及其安全研究
The Research on Authenticated Key Agreement Protocol and Its Security
【作者】 匡华清;
【作者基本信息】 湖南大学 , 计算机软件与理论, 2006, 硕士
【摘要】 基于Diffie-Hellman的AK和AKC协议得到了很大的发展,但许多协议仍有一定的安全缺陷。本文重点以Law等人给AK和AKC协议定义的安全性质来分析协议,找出协议的安全缺陷,然后提出新的认证密钥协商协议,并分别对它们建立合适的形式化模型,最后证明它们是安全的协议。具体工作如下:首先,分析了SAKA协议,由于协议参与者双方的认证码完全依赖于长期共享密钥,因此它不具有密钥泄漏的安全性。基于此,提出一种基于ECC的可证明安全的认证密钥协商协议——SEAK协议。在新协议中,协议起始方的认证码依赖于长期共享密钥,但协议的应答方的认证码依赖于会话密钥,且会话密钥是由长期共享密钥、长期私钥与临时公钥的积和临时私钥与长期公钥的积三部分串起来的哈希值,这就保证它具有密钥泄漏的安全性。同时还对SEAK协议做了启发式安全分析和性能分析,并给其建立了形式化模型,在ECCDH和随机预言模型下,证明了它是安全的。其次,对UAP协议进行安全分析,由于其确认密钥完全依赖于服务器的长期私钥,因此它不具有前向保密性和密钥泄漏的安全性。基于此,提出一种基于ECC的可证明安全的AKC协议——SAKC协议。在新协议中,加入了密钥确认,其确认密钥由长期私钥与临时公钥的积和临时私钥与长期公钥的积串起来的哈希值,这确保它具有前向保密性和密钥泄漏的安全性。同时还对SAKC协议做了启发式安全分析和性能分析,并给其建立了形式化模型,在ECCDH和随机预言模型下,证明了它是安全的。最后,针对n个群成员的EAGKA协议,总共需要n(n-1)次密钥协商和签名验证的缺点,提出了一种基于Schnorr的高效的认证群密钥协商协议——SEAGKA协议。在新协议中,签名为强签名方案,保证了群密钥的完全认证。另外,不管群成员n为多少,每一个成员Mi只需一次签名和一次验证,即签名和验证签名的次数独立于群中成员个数。还对SEAGKA协议进行了安全分析,在GDDH和随机预言模型下,证明了它是安全的协议。
【Abstract】 Numerous Diffie-Hellamn based AK and AKC protocol have been proposed, however, many have subsequently been found to have some security flaws. By the Security attributes of AK and AKC protocols defined by Law et al, this paper emphasizes on analyzing some protocols. Firstly, find some security flaws, and new authenticated key agreement protocols are proposed. Secondly, formal models of these prorocols are provided, and then these protocols proposed are proven secure within this framework in the random oracle model. List as follows:Firstly, the SAKA protocol is analysed, because the authentication codes of the two protocol participants completely lie on the long-term shared key, so it does not resist key-compromise impersonation. In this paper, an elliptic curve cryptography based provably-secure authenticated key agreement is proposed, namely, SEAK protocol. In this new protocol, the authentication code of the its initiator depend on the shared long term key, but the authentication code of the its responder relies on session key, and the session key is a hashed value of concatenation of the long-term shared key, the scalar multiplication of the long-term private key and ephemeral public key, and the scalar multiplication of the private key and long-term public key, which ensure that the protocol resists key-compromise impersonation. Also, heuristic analysis of security and performance analysis are made on the SEAK protocol, and an appropriate formal model is provided, the protocol is proven secure in ECCDH and the random oracle model.Secondly, the UAP protocol is analysed, because the key confirmation completely lies on the long-term private key, so it does not achieve forward secrecy, and resists key-compromise impersonation. In this paper, an ECC based provably-secure AKC is proposed, namely, SAKC protocol. In this new protocol, The key confirmation is incorporated into the authenticated key agreement, and its key confirmation is a hashed value of concatenation of the scalar multiplication of the long-term private key and ephemeral public key, and the scalar multiplication of the private key and long-term public key, which ensure that the protocol achieves forward secrecy, and resists key-compromise impersonation. Also, a heuristic analysis of security and performance analysis is made on the SAKC protocol, and an appropriate formal model is provided, the protocol is proven secure in ECCDH and the random oracle model.Lastly, in the EAGKA protocol that holds n group members, and total key agreements are n ( n -1), so the efficiency of the protocol is very low, when n is
- 【网络出版投稿人】 湖南大学 【网络出版年期】2006年 11期
- 【分类号】TP393.08
- 【被引频次】4
- 【下载频次】256