对原始Yahalom-Paulson协议和Backes与Pfitzmann的简化Yahalom-Paulson协议进行分析,指出各自协议中存在的漏洞.原始协议中存在类型缺陷攻击,简化协议中存在重放攻击导致协议参与实体间会话密钥不一致.对Yahalom-Paulson协议作出改进并使用串空间理论证明改进后协议的正确性.
A detailed analysis of the original Yahalom-Paulson protocol and its simplified version given by Backes and Pfitzmann was presented.It was found that there exists a type flaw attack on the original one and the simplified one can not guarantee the agreement on new session keys between legitimate parties due to replay attacks.The protocol was adapted and the new version was proved correct based on strand space theory.