论文部分内容阅读
基于认证测试方法及strand space模型,形式化分析了具有完美前向机密性的鲁棒电子邮件协议,指出该协议存在安全缺陷.同时给出了针对该协议的中间人攻击方法,即攻击者在协议的接收阶段通过伪造消息即可欺骗通信双方,使通信双方与其共享错误的会话密钥,由此使得协议的完美前向机密性得不到保证.针对协议的上述缺陷,提出一种改进方案,即通过在协议的接收阶段加入相应的签名信息,以保证改进协议能够克服中间人攻击并且提供完美前向机密性.最后,基于认证测试方法及strand space模型,形式化证明了改进协议在发起者、接收者及服务器之间的安全认证,确保了改进协议具备真正的完美前向机密性.
Based on the authentication test method and the strand space model, a robust e-mail protocol with perfect forward confidentiality is formally analyzed, and its security flaw is pointed out. At the same time, a man-in-the-middle attack method is given, , The fake message can be used to deceive the two parties in communication so that both communication parties can share the wrong session key with each other so that the perfect forward confidentiality of the protocol can not be guaranteed.According to the above defects of the protocol, an improved scheme is proposed, That is, by adding the corresponding signature information in the receiving phase of the protocol to ensure that the improved protocol can overcome the man-in-the-middle attack and provide the perfect forward confidentiality.Finally, based on the certification testing method and the strand space model, formally prove that the improved protocol is at the initiator, The secure authentication between the recipient and the server ensures that the improved protocol has true perfect forward secrecy.