Cryptanalysis of Ateniese-Steiner-Tsudik-Authenticated Group Key Management Protocol

被引:0
|
作者
Portela, Daniel Camazon [1 ]
Sanchez, Alvaro Otero [1 ]
Lopez-Ramos, Juan Antonio [1 ]
机构
[1] Univ Almeria, Dept Math, Almeria 04120, Spain
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 18期
关键词
cryptography; authenticated group key agreement; active attack; security model; elliptic curves; AGREEMENT; SECURE;
D O I
10.3390/app14188179
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
We present an active attack that targets Ateniese et al.'s authenticated group key agreement, which, as a particular case, includes the well-known multiparty key exchange protocol CLIQUES that allows a group of users to build a common secret using some private values in a collaborative and distributed way, naturally extending the foundational key exchange introduced by Diffie and Hellman between two communicating parties that motivated the birth of public key cryptography. Ateniese et al.'s protocol adds some authentication information, allowing the parties to trust the exchanged information, but we show that it is possible to surpass this as well. The attack allows a malicious party to agree on a secret with the rest of the legal members of the group without their knowledge, so all the distributed information can be accessed using this secret. In addition, this is shown under a well-known cryptographic model that, in principle, requires absolute control of group communications, but, in fact, it only requires malicious control of the communications of a single arbitrary user and only for the duration of the key exchange. This means that after the attack, the malicious party does not have to take any other actions that could reveal a clue that an attack occurred and that the distributed information is being illegally accessed, contrary to a typical man-in-the-middle attack where the attacker has to continue the activity, meaning this could be detected at some point.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] Certificateless authenticated Group Key Agreement protocol for dynamic groups
    Heo, Sungchul
    Kim, Zeen
    Kim, Kwangjo
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 464 - 468
  • [32] A novel authenticated group key agreement protocol for mobile environment
    Jia-Lun Tsai
    annals of telecommunications - annales des télécommunications, 2011, 66 : 663 - 669
  • [33] Cryptanalysis of a Group Key Transfer Protocol Based on Secret Sharing
    Nam, Junghyun
    Kim, Moonseong
    Paik, Juryon
    Jeon, Woongryul
    Lee, Byunghee
    Won, Dongho
    FUTURE GENERATION INFORMATION TECHNOLOGY, 2011, 7105 : 309 - +
  • [34] Authenticated Group Key Transfer Protocol Based on Secret Sharing
    Harn, Lein
    Lin, Changlu
    IEEE TRANSACTIONS ON COMPUTERS, 2010, 59 (06) : 842 - 846
  • [35] Authenticated Asymmetric Group Key Agreement Protocol and Its Application
    Zhang, Lei
    Wu, Qianhong
    Qin, Bo
    2010 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2010,
  • [36] An Improved Secure Certificateless Authenticated Group Key Agreement Protocol
    Geng, Manman
    Zhang, Futai
    2009 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND INTELLIGENT SYSTEMS, PROCEEDINGS, VOL 3, 2009, : 337 - 341
  • [37] An Authenticated Group Key Transfer Protocol Based on Secret Sharing
    Sun, Yi
    Wen, Qiaoyan
    Sun, Hongxiang
    Li, Wenmin
    Jin, Zhengping
    Zhang, Hua
    2012 INTERNATIONAL WORKSHOP ON INFORMATION AND ELECTRONICS ENGINEERING, 2012, 29 : 403 - 408
  • [38] Cryptanalysis of a communication-efficient three-party password authenticated key exchange protocol
    Wu, Shuhua
    Pu, Qiong
    Wang, Shengbao
    He, Debiao
    INFORMATION SCIENCES, 2012, 215 : 83 - 96
  • [39] Cryptanalysis and Design of a Three-Party Authenticated Key Exchange Protocol Using Smart Card
    Ruhul Amin
    G. P. Biswas
    Arabian Journal for Science and Engineering, 2015, 40 : 3135 - 3149
  • [40] Cryptanalysis and improvement of gateway-oriented password authenticated key exchange protocol based on RSA
    School of Electronics Engineering and Computer Science, Peking University, Beijing
    100871, China
    不详
    102600, China
    Tien Tzu Hsueh Pao, 1 (176-184):