为了保障信息在无线系统中的安全传输,用户和服务器在交换信息之前需要相互认证,并在建立1个共享的会话密钥。对邓方民提出的基于椭圆曲线的相互认证和密钥建立协议的安全性进行分析,指出协议本身存在的安全隐患。
In a wireless mobile communication system, users and network servers need to authenticate one another and agreement on a session key used for encryption purposes in their conversation. This paper provides security analysis of a mutual authentication and key establishment protocol for wireless communication based on elliptic curve cryptography. Unfortunately proposed by Fangmin Deng et al., then pointed out that their protocol does not achieve some essential security requirement including forward secrecy, impersonation attack and man-in-middle attack.