透過您的圖書館登入
IP:18.117.183.252
  • 期刊
  • OpenAccess

A Security Analysis of Two Remote User Authentication Schemes Using Bilinear Pairings

兩個基於雙線性配對的遠端使用者身分鑑別方法之安全分析

摘要


本文指出兩個基於雙線性配對的遠端使用者身分鑑別方法是不安全的。首先,我們將敘述一個身分鑑別方法,並說明其將遭受偽裝攻擊,惡意敵手截取合法使用者的有效登入資料,加以修改,偽裝此合法使用者通過身分鑑別,並且成功登入遠端系統。其次,我們指出另一基於雙線性配對的遠端使用者身分鑑別方法將遭受離線攻擊,在截取同一使用者兩個不同的有效登入資料,但二者具同一由使用者選定的任意參數,攻擊者將能算出合法使用者的身分鑑別機密資料,最後達到成功偽裝此合法使用者的目的。

並列摘要


In this paper, we indicate two pairing-based remote user authentication scheme are insecure. First, a proposed authentication scheme suffers from the impersonation attack. The malicious adversary intercepts valid information from the login request, modifies it, and is able to impersonate the legitimate user to pass the authentication. Secondly, we also point out another authentication scheme, using bilinear pairing and elliptic curve cryptography, will suffer from the off-line dictionary attack. Under the user selecting the same random number for two distinct login, the attacker could calculate out the private secret of the user, and impersonate to be the legitimate user to login the system.

延伸閱讀