Remarks on the Unknown Key Share Attacks
Joonsang Baek, Kwangjo Kim · 2000
Introduction An UKS attack on key agreement protocols is an attack whereby an entity A finishes an execution of a key agreement protocol believing that a common key is shared with an entity B (this is in fact the case) but B falsely believes that the key is shared with another entity E ( j = A). The attack scenario first described in [6] is as follows: Suppose that B is a bank branch and A is an account holder. Certificates are issued by the bank headquarters and identifying information of the holder is contained in each certificate. Also, suppose that the protocol for electronic deposit of funds involves exchanging a key with a bank branch via a key agreement protocol. At the end of the protocol execution, encrypted funds are deposited into the account number in the certificate. Assume that no further authentication is done in the encrypted deposit