在无线系统中,用户和服务器需要进行彼此认证并建立一个共享会话密钥。该密钥为用户和服务器后面的会话提供安全保证。Aydos提出了一种建立在ECC上的相互认证和密钥建立协议,并适用于无线网络的应用。通过对Aydos协议的研究发现该协议并不能满足前向保密性、中间人攻击以及假冒攻击的安全性要求。
In a wireless mobile communication system, users and network servers need to authenticate one another and reach agreement on a session key for encrypfion purposes in their conversation. Aydos et al. proposed a mutual authentication and key establishment protocol for wireless communication based on elliptic curve cryptography. Unfortunately, by our cryptanalysis we find Aydos' protocol does not achieve some essential security requirement including forward secrecy, impersonation attack and man- in- middle attack.