
第35卷第9期 2012年9月
计算机学报
CHINESEJOURNALOFCOMPUTERS
带认证邮局协议的密钥恢复攻击
刘凡保”谢涛”冯登国”》(国防科学技术大学计算机学院长沙410073) 2)(中国科学院信息安全国家重点实验室北京100190)
Vol.35No.9
Sept.2012
摘要作者提出了种新的针对带认证邮局协议的密钥恢复攻击,能够更快地恢复出密钥并能够恢复更多的密钥字符.基于通道技术和高级消息修改技术,提出了一种“群满足方案”来确定性地满足分而治之策略下最后一个通道首三步的所有充分条件,籍此提高MD5(MessageDigestAlgorithm5)碰撞对搜索的效率.并提出了一些新的通道来控制MD5硅撑对消息的更多比特的取值,比如可以构造出352比特值确定的MD5碰撞对.通过这些技术
的密钥,而且能够在实际时间内恢复长达43个字符的密钥,
带认证邮局协议;挑战和响应;密钥恢复;通道,群满足方案
关键词营
中图法分类号TP309
DOI号:10.3724/SP.J.1016.2012.01927
PasswordRecoveryAttacktoAuthenticationPostOfficeProtocol
LIU Fan-Bao'"XIE Tao"FENG Deng-Guo"
(Schol of Com puter, National Usitersity of Defense Techmology, Changsha410073)
(State Key Laboratory of Information Security, Chinese Academy of Sciences, Beijing100190)
Abstract
In this paper, we propose a new password recovery attack to Authentication Post
Office Protocol(APOP), which can recover more password characters and faster. First, based on e Scheme"to satisfy determinately all conditions of the first three successive steps of the last tun-nel, to further improve Message Digest Algorithm 5 (MD5) collision searching efficiency.Sec ond, we propose some new tunnels to generate more meaningful characters during MD5 collision searching; for example, we can construct an MD5 collision pair with as many as 352 fixed bits. Combining with these technologies, we can improve the efficiency of MD5 collision searching with high number of chosen bits, hence, we can recover APOP passwords with 31 characters extreme-ly fast, and can also recover passwords as long as 43 characters in practical time.
Keywordsauthentication post office protocol; challenge and response; password recovery; tun-nel; group satisfaction scheme
言
1
引
带认证邮局协议(AuthenticationPostOffice
Protocol——-Version3,APOP)[被广泛应用于邮局协议—版本3(POP3)以提供用户原始身份验证和抗重放攻击.APOP是基于散列函数MD5的挑战和响应的密钥认证协议.APOP的身份认证包
收稿日期:2012-05-18;最终修改稿收到口期:2012-07-11.本课题得到国家核高基重大专项课题(2010ZX01037-001-001)、国家“九七兰" 861(82019性20280200
向为密码分析、网络安全和可信计算,E-mail:liufanbao①gmail.com,谢
涛,男,1966年生,博士,研究员,主要研究领域为演化计算、密
961 万方数据