论文标题

事实证明,不安全的团体身份验证:并非所有安全证明都是他们声称的

Provably insecure group authentication: Not all security proofs are what they claim to be

论文作者

Mitchell, Chris J

论文摘要

在ICICS 2019会议上发表的一篇论文描述了所谓的“在异步通信模型中证明是安全的团体身份验证[协议]”。我们在这里表明情况远非如此,因为该协议受到严重攻击。为了解释这一令人不安的案例,还检查了ICICS 2019协议的早期(2013年)计划,并发现该方案具有更严重的缺陷 - 后者以前众所周知,该计划受到攻击,但并不是此处所示的基本方式。对2013年和2019年论文中提供的安全定理的审查表明,在这两种情况下,它们似乎都始终是它们的目的。还简要讨论了这一问题。

A paper presented at the ICICS 2019 conference describes what is claimed to be a `provably secure group authentication [protocol] in the asynchronous communication model'. We show here that this is far from being the case, as the protocol is subject to serious attacks. To try to explain this troubling case, an earlier (2013) scheme on which the ICICS 2019 protocol is based was also examined and found to possess even more severe flaws - this latter scheme was previously known to be subject to attack, but not in quite as fundamental a way as is shown here. Examination of the security theorems provided in both the 2013 and 2019 papers reveals that in neither case are they exactly what they seem to be at first sight; the issues raised by this are also briefly discussed.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源