Cryptanalysis of Ateniese-Steiner-Tsudik-Authenticated Group Key Management Protocol

被引:0
|
作者
Portela, Daniel Camazon [1 ]
Sanchez, Alvaro Otero [1 ]
Lopez-Ramos, Juan Antonio [1 ]
机构
[1] Univ Almeria, Dept Math, Almeria 04120, Spain
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 18期
关键词
cryptography; authenticated group key agreement; active attack; security model; elliptic curves; AGREEMENT; SECURE;
D O I
10.3390/app14188179
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
We present an active attack that targets Ateniese et al.'s authenticated group key agreement, which, as a particular case, includes the well-known multiparty key exchange protocol CLIQUES that allows a group of users to build a common secret using some private values in a collaborative and distributed way, naturally extending the foundational key exchange introduced by Diffie and Hellman between two communicating parties that motivated the birth of public key cryptography. Ateniese et al.'s protocol adds some authentication information, allowing the parties to trust the exchanged information, but we show that it is possible to surpass this as well. The attack allows a malicious party to agree on a secret with the rest of the legal members of the group without their knowledge, so all the distributed information can be accessed using this secret. In addition, this is shown under a well-known cryptographic model that, in principle, requires absolute control of group communications, but, in fact, it only requires malicious control of the communications of a single arbitrary user and only for the duration of the key exchange. This means that after the attack, the malicious party does not have to take any other actions that could reveal a clue that an attack occurred and that the distributed information is being illegally accessed, contrary to a typical man-in-the-middle attack where the attacker has to continue the activity, meaning this could be detected at some point.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] Cryptanalysis of a Three-party Authenticated Key Exchange Protocol Using Elliptic Curve Cryptography
    Pu, Qiong
    Zhao, Xiuying
    Ding, Jianmin
    2009 INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN COMPUTER SCIENCE, ICRCCS 2009, 2009, : 7 - 10
  • [42] Cryptanalysis and Design of a Three-Party Authenticated Key Exchange Protocol Using Smart Card
    Amin, Ruhul
    Biswas, G. P.
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2015, 40 (11) : 3135 - 3149
  • [43] Cryptanalysis of a new efficient authenticated multiple-key exchange protocol from bilinear pairings
    Cheng, Qingfeng
    International Journal of Network Security, 2014, 16 (06) : 494 - 497
  • [44] Cryptanalysis and Improvement of a Password-Based Authenticated Three-Party Key Exchange Protocol
    Lee, Youngsook
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (04): : 151 - 160
  • [45] Attribute-Based Authenticated Group Key Management Protocol for Mobile Peer-to-Peer Network
    Zhang Guoyin
    Fu Xiaojing
    Ma Chunguang
    CHINA COMMUNICATIONS, 2012, 9 (10) : 68 - 77
  • [46] A Certificateless Authenticated Group Key Agreement Protocol providing Forward Secrecy
    Lee, Eun-Jung
    Lee, Sang-Eon
    Yoo, Kee-Young
    INTERNATIONAL SYMPOSIUM ON UBIQUITOUS MULTIMEDIA COMPUTING, PROCEEDINGS, 2008, : 124 - +
  • [47] Dynamic tree-based authenticated group key exchange protocol
    Li Hui
    Wu ChuanKun
    Teng Jikai
    SCIENCE CHINA-INFORMATION SCIENCES, 2010, 53 (08) : 1591 - 1602
  • [48] Identity-Based Authenticated Asymmetric Group Key Agreement Protocol
    Zhang, Lei
    Wu, Qianhong
    Qin, Bo
    Domingo-Ferrer, Josep
    COMPUTING AND COMBINATORICS, 2010, 6196 : 510 - 519
  • [49] Authenticated Group Key Agreement Protocol for Unbalanced Wireless Mobile Networks
    Lu, Chung-Fu
    Wu, Tzong-Chen
    Shih, Tzay-Farn
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON COMPLEX, INTELLIGENT AND SOFTWARE INTENSIVE SYSTEMS (CISIS 2010), 2010, : 827 - 832
  • [50] A Hybrid Authenticated Group Key Agreement Protocol in Wireless Sensor Networks
    Li, Yue
    Chen, Dehua
    Li, Wei
    Wang, Gaoli
    Smith, Paul
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2013,