An optimized authentication protocol for mobile network reconsidered

Duncan S. Wong · ACM SIGMOBILE Mobile Computing and Communications Review · 2002

In [6], an authenticated key transport protocol was proposed for establishing secure communications between a base station and a mobile unit. The protocol is public-key based and relies on certificates to validate public keys of communicating parties. A signature scheme was also proposed and used in the certification mechanism of the protocol. We find that the signature scheme is vulnerable to an attack which allows an adversary to generate a signature on any message at its will. In this paper, we describe the attack and explain how the entire system can be compromised by an intruder after eavesdropping only one single run of the protocol.

Read the paper · More papers on PaperTik