首页 | 官方网站   微博 | 高级检索  
     

带认证邮局协议的密钥恢复攻击
引用本文:刘凡保,谢涛,冯登国.带认证邮局协议的密钥恢复攻击[J].计算机学报,2012,35(9):1927-1937.
作者姓名:刘凡保  谢涛  冯登国
作者单位:1. 国防科学技术大学计算机学院 长沙410073
2. 中国科学院信息安全国家重点实验室 北京100190
基金项目:国家核高基重大专项课题,国家“九七三”重点基础研究发展规划项目基金,国家自然科学基金
摘    要:作者提出了一种新的针对带认证邮局协议的密钥恢复攻击,能够更快地恢复出密钥并能够恢复更多的密钥字符.基于通道技术和高级消息修改技术,提出了一种“群满足方案”来确定性地满足分而治之策略下最后一个通道首三步的所有充分条件,籍此提高MD5 (Message Digest Algorithm 5)碰撞对搜索的效率.并提出了一些新的通道来控制MD5碰撞对消息的更多比特的取值,比如可以构造出352比特值确定的MD5碰撞对.通过这些技术改进了多位信息确定的MD5碰撞对搜索效率,应用到APOP的密钥恢复攻击中不仅能够快速恢复长达31个字符的密钥,而且能够在实际时间内恢复长达43个字符的密钥.

关 键 词:带认证邮局协议  挑战和响应  密钥恢复  通道  群满足方案

Password Recovery Attack to Authentication Post Office Protocol
LIU Fan-Bao , XIE Tao , FENG Deng-Guo.Password Recovery Attack to Authentication Post Office Protocol[J].Chinese Journal of Computers,2012,35(9):1927-1937.
Authors:LIU Fan-Bao  XIE Tao  FENG Deng-Guo
Affiliation:1)(School of Computer,National University of Defense Technology,Changsha 410073)2)(State Key Laboratory of Information Security,Chinese Academy of Sciences,Beijing 100190)
Abstract:In this paper,we propose a new password recovery attack to Authentication Post Office Protocol(APOP),which can recover more password characters and faster.First,based on tunnel and advanced message modification technologies,we propose a "Group Satisfaction Scheme"to satisfy determinately all conditions of the first three successive steps of the last tunnel,to further improve Message Digest Algorithm 5(MD5) collision searching efficiency.Second,we propose some new tunnels to generate more meaningful characters during MD5 collision searching;for example,we can construct an MD5 collision pair with as many as 352 fixed bits.Combining with these technologies,we can improve the efficiency of MD5 collision searching with high number of chosen bits,hence,we can recover APOP passwords with 31 characters extremely fast,and can also recover passwords as long as 43 characters in practical time.
Keywords:authentication post office protocol  challenge and response  password recovery  tunnel  group satisfaction scheme
本文献已被 CNKI 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号