• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Liu, Fanbao (Liu, Fanbao.)

收录:

EI Scopus

摘要:

Digest Access Authentication was originally proposed to provide peer authentication and data encryption in HTTP protocols. It has been widely employed along with the deployment of SASL. In this paper, we implement a password recovery attack to Digest Access Authentication that can recover passwords as long as 48 characters in overall off-line computation about 2 35 MD5 compressions and 8084 on-line queries. This confirms that the security of Digest Access Authentication is totally broken, and all applications based on that must be re-evaluated seriously. Further, we prove that the security of the hashing scheme H(CP), where H is a hash function, C is a challenge and P is a shared password, is totally dependent on the collision resistance of H, instead of the pre-image resistance. Such scheme can't be used in challenge and response protocols to protect the shared password. Finally, we prove that some hashing schemes like H(H(CP)) provide no more security than H(CP), in the aspect of collision resistance. © 2011 IEEE.

关键词:

Authentication Computer system recovery Hash functions Recovery Ubiquitous computing

作者机构:

  • [ 1 ] [Liu, Fanbao]School of Computer, National University of Defense Technology, Changsha, 410073, Hunan, China
  • [ 2 ] [Liu, Fanbao]School of Computer, Beijing University of Technology, 100124, Beijing, China

通讯作者信息:

电子邮件地址:

查看成果更多字段

相关关键词:

相关文章:

来源 :

年份: 2011

页码: 427-434

语种: 英文

被引次数:

WoS核心集被引频次: 0

SCOPUS被引频次: 10

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 2

在线人数/总访问数:657/2896660
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司