DocumentCode
2028204
Title
On the security of the ECKE-1N and EECKE-1N elliptic-curve key agreement protocols
Author
Strangio, Maurizio Adriano
Author_Institution
Dept. of Math., Univ. of Rome “Roma Tre”, Rome, Italy
fYear
2011
fDate
6-8 Sept. 2011
Firstpage
259
Lastpage
263
Abstract
In a recent paper published in the proceedings of the EBISS´09 conference, Mohammad and Chi-Chun Lo claim that protocol ECKE-1N is vulnerable to key compromise impersonation (KCI) attacks and ephemeral key leakage. They also present protocol EECKE-1N, a revised version of protocol ECKE-1N, which is supposedly more secure since it does not exhibit similar vulnerabilities. In this article we show that the results concerning the security properties of the ECKE-1N protocol described in the aforementioned work were not correctly established. In particular, the first attack against protocol ECKE-1N does not demonstrate its vulnerability to KCI attacks while the second attack cannot be successfully brought against the protocol under the assumptions of the formal security model considered by the authors. We also present protocol ECKE-1H, a stronger version of the ECKE-1N protocol, and prove its security in the extended Canetti-Krawczyck model of distributed computing introduced by Lamacchia et al.
Keywords
cryptographic protocols; public key cryptography; Canetti-Krawczyck model; ECKE-1H; ECKE-1N; EECKE-1N; distributed computing; elliptic curve key agreement protocols; formal security model; key compromise impersonation; Computational modeling; Elliptic curve cryptography; Elliptic curves; Mathematical model; Protocols;
fLanguage
English
Publisher
ieee
Conference_Titel
Network and System Security (NSS), 2011 5th International Conference on
Conference_Location
Milan
Print_ISBN
978-1-4577-0458-1
Type
conf
DOI
10.1109/ICNSS.2011.6060011
Filename
6060011
Link To Document