vix.ing · top · new · best · stats · spec

The Saeed-Liu-Tian-Gao-Li authenticated key agreement protocol is insecure

2019/06/21 by Chris J. Mitchell, Mitchell, Chris J · 1 citation
Computer Science · #Advanced Authentication Protocols Security #Cryptography and Data Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Security in Wireless Sensor Networks

paper · pdf · doi:10.48550/arxiv.1906.09330

openalex publication_date 2019/06/21 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

A recently proposed authenticated key agreement protocol is shown to be insecure. In particular, one of the two parties is not authenticated, allowing an active man in the middle opponent to replay old messages. The protocol is essentially an authenticated Diffie-Hellman key agreement scheme, and the lack of authentication allows an attacker to replay old messages and have them accepted. Moreover, if the ephemeral key used to compute a protocol message is ever compromised, then the key established using the replayed message will also be compromised. Fixing the problem is simple - there are many provably secure and standardised protocols which are just as efficient as the flawed scheme.

Cited by

Related