论文标题

评论“基于不可靠的网络,可证明基于生物识别的客户服务器安全通信”

Comment on "Provably secure biometric-based client-server secure communication over unreliable networks"

论文作者

Nikooghadam, Mahdi, Shahriari, Hamid Reza

论文摘要

在关键协议协议中,用户将向服务器发送请求,服务器将响应该消息。双向身份验证后,将在它们之间创建一个安全的会话密钥。他们使用会话密钥创建一个安全的通信通道。在2021年,Saleem等人。提出了用于确保用户和服务器通信的协议,声称其建议的协议满足了各种安全需求,并且还可以抵抗已知类型的攻击。在本文中,我们将表明Saleem等人的计划不符合完美远期保密的安全要求。

In key agreement protocols, the user will send a request to the server and the server will respond to that message. After two-way authentication, a secure session key will be created between them. They use the session key to create a secure channel for communication. In 2021, Saleem et al. proposed a protocol for securing user and server communications, claiming that their proposed protocol meets a variety of security needs and is also resistant to known types of attacks. In this article, we will show that Saleem et al's scheme does not meet the security requirement of perfect forward secrecy.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源