DOI QR코드

DOI QR Code

Cross-Realm 환경에서 패스워드기반 키교환 프로토콜

Password-Based Key Exchange Protocols for Cross-Realm

  • Lee, Young Sook (Department of Cyber Investigation Police, Howon University)
  • 투고 : 2009.11.06
  • 심사 : 2009.12.05
  • 발행 : 2009.12.30

초록

Authentication and key exchange are fundamental for establishing secure communication channels over public insecure networks. Password-based protocols for authenticated key exchange are designed to work even when user authentication is done via the use of passwords drawn from a small known set of values. There have been many protocols proposed over the years for password authenticated key exchange in the three-party scenario, in which two clients attempt to establish a secret key interacting with one same authentication server. However, little has been done for password authenticated key exchange in the more general and realistic four-party setting, where two clients trying to establish a secret key are registered with different authentication servers. In fact, the recent protocol by Yeh and Sun seems to be the only password authenticated key exchange protocol in the four-party setting. But, the Yeh-Sun protocol adopts the so called "hybrid model", in which each client needs not only to remember a password shared with the server but also to store and manage the server's public key. In some sense, this hybrid approach obviates the reason for considering password authenticated protocols in the first place; it is difficult for humans to securely manage long cryptographic keys. In this work, we introduce a key agreement protocol and a key distribution protocol, respectively, that requires each client only to remember a password shared with its authentication server.

키워드

과제정보

연구 과제 주관 기관 : Howon University