Attacks on An ISO/IEC 11770-2 Key Establishment Protocol

Zhaohui Cheng, Richard Comley · IACR Cryptology ePrint Archive · 2005

This paper demonstrates that two types of serious attack (replay and type) are possible on an ISO/IEC server-based key establishment protocol. The flaw is associated with the method used to ensure the freshness of an established key. Two possible solutions are proposed to deal with the identified weakness. This is of great potential impact and as a result of this work, ISO published a technical corrigendum (ISO/IEC 11770-2:1996/Cor 1:2005) to remove the protocol from ISO/IEC 11770-2: 1996.

Read the paper · More papers on PaperTik