About Validity Checks of Augmented PAKE in IEEE 1363.2 and ISO/IEC 11770-4

被引:0
|
作者
Shin, SeongHan [1 ]
Kobara, Kazukuni [1 ]
机构
[1] Natl Inst Adv Ind Sci & Technol, Res Inst Secure Syst RISEC, Tsukuba, Ibaraki 3058568, Japan
关键词
PAKE; on-line/off-line dictionary attacks; augmented PAKE; IEEE; 1363.2; ISO/IEC; 11770-4; validity checks;
D O I
10.1587/transfun.E97.A.413
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
An augmented PAKE (Password-Authenticated Key Exchange) protocol provides password-only authentication in the presence of an attacker, establishment of session keys between the involving parties, and extra protection for server compromise (i.e., exposure of password verification data). Among many augmented PAKE protocols, AMP variants (AMP2 [16] and AMP(+) [15]) have been standardized in IEEE 1363.2 [9] and ISO/IEC 11770-4 [10]. In this paper, we thoroughly investigate APKAS-AMP (based on AMP2 [16]) and KAM3 (based on AMP(+) [15]) which require several validity checks on the values, received and computed by the parties, when using a secure prime. After showing some attacks on APKAS-AMP and KAM3, we suggest new sanity checks that are clear and sufficient to prevent an attacker from doing these attacks.
引用
收藏
页码:413 / 417
页数:5
相关论文
共 1 条
  • [1] A Combined ISO/IEC/IEEE 21451-4 and-2 Data Acquisition Module
    Ma, Yuan
    Cherian, Avarachan
    Wobschall, Darold
    [J]. 2017 IEEE SENSORS APPLICATIONS SYMPOSIUM (SAS), 2017,