Cryptanalysis of Arshad et al.'s ECC-based mutual authentication scheme for session initiation protocol

被引:26
|
作者
Tang, Hongbin [1 ]
Liu, Xinsong [1 ]
机构
[1] Univ Elect Sci & Technol China, Sch Comp Sci & Engn, Chengdu 610054, Peoples R China
关键词
Password guessing attack; Session initiation protocol; Elliptic curve cryptography; Authentication; Protocol; Cryptography;
D O I
10.1007/s11042-012-1001-8
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Session Initiation Protocol (SIP) has been widely used in the current Internet protocols such as Hyper Text Transport Protocol (HTTP) and Simple Mail Transport Protocol (SMTP). However, the original SIP authentication scheme was insecure and many researchers tried to propose schemes to overcome the flaws. In the year 2011, Arshad et al. proposed a SIP authentication protocol using elliptic curve cryptography (ECC), but their scheme suffered from off-line password guessing attack along with password change pitfalls. To conquer the mentioned weakness, we proposed an ECC-based authentication scheme for SIP. Our scheme only needs to compute four elliptic curve scale multiplications and two hash-to-point operations, and maintains high efficiency. The analysis of security of the ECC-based protocol shows that our scheme is suitable for the applications with higher security requirement.
引用
收藏
页码:321 / 333
页数:13
相关论文
empty
未找到相关数据