The original paper is in English. Non-English content has been machine-translated and may contain typographical errors or mistranslations. ex. Some numerals are expressed as "XNUMX".
Copyrights notice
The original paper is in English. Non-English content has been machine-translated and may contain typographical errors or mistranslations. Copyrights notice
Des protocoles d'authentification sont nécessaires pour que le destinataire d'un message puisse vérifier son origine dans un environnement distribué. Puisqu’ils échangent des messages cryptographiques dès le début de la communication, leur sécurité est une exigence essentielle. Cependant, la plupart des protocoles ont subi plusieurs types d’attaques. Une attaque par rejeu est un type de ces attaques. Les attaquants pourraient le lancer facilement en rejouant un message écouté. De plus, il existe de nombreux types d’attaques par rejeu alors que la plupart des méthodes formelles ne sont pas capables de les détecter. [3] ont classé différents types d'attaques par rejeu et ont proposé une taxonomie. Il est donc nécessaire de vérifier délibérément les protocoles d’authentification sur la base d’une telle taxonomie. Dans cet article, nous donnons dans un premier temps une définition claire et quelques remarques sur les attaques par rejeu. Deuxièmement, nous passons en revue la taxonomie des attaques par rejeu présentée dans [3], et commentons son erreur mineure. Enfin, nous examinons, sur la base de la taxonomie, le protocole d'authentification par mot de passe, K1P, proposé dans nos articles précédents pour protéger efficacement les secrets faibles. À la suite de l’examen, nous avons découvert que le K1P mutuel à trois voies présenté dans [2] était vulnérable à l’une des attaques par rejeu. Par conséquent, nous améliorons le K1P à trois voies en termes de sécurité contre les attaques par relecture. Le K1P à trois voies amélioré est sécurisé contre les attaques par rejeu ainsi que contre les attaques par devinette et peut donc être utile pour les services de sécurité de divers réseaux de communication.
The copyright of the original papers published on this site belongs to IEICE. Unauthorized use of the original or translated papers is prohibited. See IEICE Provisions on Copyright for details.
Copier
Taekyoung KWON, Myeongho KANG, Sangjoon JUNG, Jooseok SONG, "An Improvement of the Password-Based Authentication Protocol (K1P) on Security against Replay Attacks" in IEICE TRANSACTIONS on Communications,
vol. E82-B, no. 7, pp. 991-997, July 1999, doi: .
Abstract: Authentication protocols are necessary for the receiver of a message to ascertain its origin in a distributed environment. Since they exchange cryptographic messages at the beginning of communication, their security is an essential requirement. However, most of the protocols have suffered from several kinds of attacks. A replay attack is one kind of those attacks. Attackers could launch it easily by replaying an eavesdropped message. Moreover, there are many types of replay attacks while most of the formal methods are not capable of detecting them. [3] classified various kinds of replay attacks and proposed a taxonomy. Therefore, it is necessary to verify authentication protocols deliberately with such a taxonomy for a basis. In this paper, at first, we give a clear definition and several remarks on replay attacks. Secondly we review the taxonomy of replay attacks presented in [3], and comment on its minor mistake. Finally we examine on the basis of the taxonomy the password-based authentication protocol, K1P, which was proposed in our earlier papers for protecting weak secrets efficiently. As a result of the examination, we have found that three way mutual K1P shown in [2] was vulnerable to one of replay attacks. Therefore, we improve three way K1P on security against the replay attack. Improved three way K1P is secure against replay attacks as well as guessing attacks and therefore it may be useful for security services of various communication networks.
URL: https://global.ieice.org/en_transactions/communications/10.1587/e82-b_7_991/_p
Copier
@ARTICLE{e82-b_7_991,
author={Taekyoung KWON, Myeongho KANG, Sangjoon JUNG, Jooseok SONG, },
journal={IEICE TRANSACTIONS on Communications},
title={An Improvement of the Password-Based Authentication Protocol (K1P) on Security against Replay Attacks},
year={1999},
volume={E82-B},
number={7},
pages={991-997},
abstract={Authentication protocols are necessary for the receiver of a message to ascertain its origin in a distributed environment. Since they exchange cryptographic messages at the beginning of communication, their security is an essential requirement. However, most of the protocols have suffered from several kinds of attacks. A replay attack is one kind of those attacks. Attackers could launch it easily by replaying an eavesdropped message. Moreover, there are many types of replay attacks while most of the formal methods are not capable of detecting them. [3] classified various kinds of replay attacks and proposed a taxonomy. Therefore, it is necessary to verify authentication protocols deliberately with such a taxonomy for a basis. In this paper, at first, we give a clear definition and several remarks on replay attacks. Secondly we review the taxonomy of replay attacks presented in [3], and comment on its minor mistake. Finally we examine on the basis of the taxonomy the password-based authentication protocol, K1P, which was proposed in our earlier papers for protecting weak secrets efficiently. As a result of the examination, we have found that three way mutual K1P shown in [2] was vulnerable to one of replay attacks. Therefore, we improve three way K1P on security against the replay attack. Improved three way K1P is secure against replay attacks as well as guessing attacks and therefore it may be useful for security services of various communication networks.},
keywords={},
doi={},
ISSN={},
month={July},}
Copier
TY - JOUR
TI - An Improvement of the Password-Based Authentication Protocol (K1P) on Security against Replay Attacks
T2 - IEICE TRANSACTIONS on Communications
SP - 991
EP - 997
AU - Taekyoung KWON
AU - Myeongho KANG
AU - Sangjoon JUNG
AU - Jooseok SONG
PY - 1999
DO -
JO - IEICE TRANSACTIONS on Communications
SN -
VL - E82-B
IS - 7
JA - IEICE TRANSACTIONS on Communications
Y1 - July 1999
AB - Authentication protocols are necessary for the receiver of a message to ascertain its origin in a distributed environment. Since they exchange cryptographic messages at the beginning of communication, their security is an essential requirement. However, most of the protocols have suffered from several kinds of attacks. A replay attack is one kind of those attacks. Attackers could launch it easily by replaying an eavesdropped message. Moreover, there are many types of replay attacks while most of the formal methods are not capable of detecting them. [3] classified various kinds of replay attacks and proposed a taxonomy. Therefore, it is necessary to verify authentication protocols deliberately with such a taxonomy for a basis. In this paper, at first, we give a clear definition and several remarks on replay attacks. Secondly we review the taxonomy of replay attacks presented in [3], and comment on its minor mistake. Finally we examine on the basis of the taxonomy the password-based authentication protocol, K1P, which was proposed in our earlier papers for protecting weak secrets efficiently. As a result of the examination, we have found that three way mutual K1P shown in [2] was vulnerable to one of replay attacks. Therefore, we improve three way K1P on security against the replay attack. Improved three way K1P is secure against replay attacks as well as guessing attacks and therefore it may be useful for security services of various communication networks.
ER -