• DocumentCode
    2028204
  • Title

    On the security of the ECKE-1N and EECKE-1N elliptic-curve key agreement protocols

  • Author

    Strangio, Maurizio Adriano

  • Author_Institution
    Dept. of Math., Univ. of Rome “Roma Tre”, Rome, Italy
  • fYear
    2011
  • fDate
    6-8 Sept. 2011
  • Firstpage
    259
  • Lastpage
    263
  • Abstract
    In a recent paper published in the proceedings of the EBISS´09 conference, Mohammad and Chi-Chun Lo claim that protocol ECKE-1N is vulnerable to key compromise impersonation (KCI) attacks and ephemeral key leakage. They also present protocol EECKE-1N, a revised version of protocol ECKE-1N, which is supposedly more secure since it does not exhibit similar vulnerabilities. In this article we show that the results concerning the security properties of the ECKE-1N protocol described in the aforementioned work were not correctly established. In particular, the first attack against protocol ECKE-1N does not demonstrate its vulnerability to KCI attacks while the second attack cannot be successfully brought against the protocol under the assumptions of the formal security model considered by the authors. We also present protocol ECKE-1H, a stronger version of the ECKE-1N protocol, and prove its security in the extended Canetti-Krawczyck model of distributed computing introduced by Lamacchia et al.
  • Keywords
    cryptographic protocols; public key cryptography; Canetti-Krawczyck model; ECKE-1H; ECKE-1N; EECKE-1N; distributed computing; elliptic curve key agreement protocols; formal security model; key compromise impersonation; Computational modeling; Elliptic curve cryptography; Elliptic curves; Mathematical model; Protocols;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and System Security (NSS), 2011 5th International Conference on
  • Conference_Location
    Milan
  • Print_ISBN
    978-1-4577-0458-1
  • Type

    conf

  • DOI
    10.1109/ICNSS.2011.6060011
  • Filename
    6060011