Standardising Authentication Protocols Based on Public Key Techniques

Chris J. Mitchell, Andy Thomas · Journal of Computer Security · 1993

ISO has been working on a multi-part authentication mechanisms standard for some years. The first part, ISO/IEC 9798-1 [15], has recently been published. Parts two and three (9798-2, [18] and 9798-3, [17]), covering authentication mechanisms based on symmetric and asymmetric cryptographic techniques respectively, are now moving towards DIS (Draft International Standard) and full International Standard status respectively. This paper is concerned with authentication mechanisms based on asymmetric cryptography; more specifically it contrasts two important authentication mechanisms from the latest version of 9798-3 and from CCITT Recommendation X.509-1988 [9], and briefly illustrates certain known attacks against this type of mechanism. A new potential security problem is then described, to which many published mechanisms appear to be prone. Possible solutions to this problem are discussed, together with potential ramifications on existing standardisation activity.

Read the paper · More papers on PaperTik