Question: Key agreement / IKE ( 1 0 - 5 - 1 0 points ) : ( a ) Consider the following key exchange protocol which
Key agreementIKE points:
a Consider the following key exchange protocol which is similar to IKE Phase Aggressive
Mode. p is a large prime number and g is a generator of Z
p
A B : ga mod pAliceBobRABob
A B : gb mod pBobAliceRBAlice proofB
A B : proofA
where
proofA hgab mod p ga mod p gb mod pAlice
proofB hgab mod p gb mod p ga mod pBob
K hgab mod p
i First explain if the protocol authenticates A and B and achieves secure key agreement
discuss key control and key authenticationmX denotes a message m encrypted with
public key of x
ii Modify the protocol so that RA and RB can be eliminated but the protocol can mutually
authenticate A and B In your modification, no additional protocol message, secret
keys or signature can be used.
b Consider the following simplified IKE Phase in Aggressive Mode.
A B : AliceBob ga mod p
A B : BobAlice gb mod pga mod pB
A B : AliceBobgb mod p ga mod pA
XA denotes a signature on message X generated by A The session key established
between A and B is gab mod p Show that this simplified version is insecure allows
attacker to establish a key with one of the participants while pretending to be the other
participant Hint: consider that this IPSec system has multiple users.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
