• DocumentCode
    2874538
  • Title

    Key Replicating Attack on Certificateless Authenticated Key Agreement Protocol

  • Author

    Hou, Mengbo ; Xu, Qiuliang

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Shandong Univ., Jinan, China
  • Volume
    2
  • fYear
    2009
  • fDate
    18-19 July 2009
  • Firstpage
    574
  • Lastpage
    577
  • Abstract
    Authenticated key agreement protocol is crucial in providing data confidentiality and integrity to subsequent communications among two or more parties over a public network. Certificateless public key cryptography (CL-PKC) combines the advantage of the identity-based public key cryptography (ID-PKC) and the traditional PKI. In 2007, Y.J Shi and J.H Li proposed a two-party authenticated key agreement protocol based on the certificateless encryption scheme proposed by B. Libert and J.J. Quisquater. It is found that the scheme is vulnerable to the key replicating attack (one form of the man-in-the-middle attack), so it doesnpsilat possess the security attribute of implicit key authentication and key control. We analyze such an attack of this protocol in the BR93 model in detail, and demonstrate that the protocol is not secure if the adversary is allowed to send a reveal query to reveal non-partner players who had accepted the same session key.
  • Keywords
    cryptographic protocols; data integrity; message authentication; public key cryptography; BR93 model; certificateless authenticated key agreement protocol; data confidentiality; data integrity; identity-based certificateless public key cryptography; implicit key authentication; key replicating attack; public network; security attribute; subsequent communication; Authentication; Computer science; Cryptographic protocols; Data privacy; Identity-based encryption; Information processing; Information security; Public key; Public key cryptography; certificateless-based cryptography; identity-based cryptography; implicit key authentication; key agreement protocol; key replicating attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Processing, 2009. APCIP 2009. Asia-Pacific Conference on
  • Conference_Location
    Shenzhen
  • Print_ISBN
    978-0-7695-3699-6
  • Type

    conf

  • DOI
    10.1109/APCIP.2009.277
  • Filename
    5197264