Jump to ContentJump to Main Navigation

Online

29,00 € / $41.00*

* Prices subject to change. Shipping costs will be added.
Publication Date:
16 05 2008
ISSN:
1862-2984
DOI:
10.1515/JMC.2007.004

See all formats and pricing

Print
List price
Euro [D] 363.00
RRP for USA, Canada, Mexico
US$ 545.00 *
Online
List price
Euro [D] 29.00
RRP for USA, Canada, Mexico
US$ 41.00 *
Print + Online
List price
Euro [D] 419.00
RRP for USA, Canada, Mexico
US$ 629.00 *
*Prices subject to change. Shipping costs will be added.

Managing Editor: Magliveras, Spyros S. / Steinwandt, Rainer / Trung, Tran

null Blackburn, Simon R. / Brickell, Ernie / Burmester, Mike / Cramer, Ronald / Dawson, Ed / Gilman, Robert / Gonzalez Vasco, Maria Isabel / Grosek, Otokar / Imai, Hideki / Kim, Kwangjo / Koblitz, Neal / Kurosawa, Kaoru / Menezes, Alfred / Mullin, Ron / Nguyen, Phong Q. / Pieprzyk, Josef / Safavi-Naini, Rei / Shparlinski, Igor / Stinson, Doug / Williams, Hugh C. / Yung, Moti

4 Issues per year

Mathematical Citation Quotient 2010: 0.31

Another look at HMQV

Menezes, Alfred 1

1 Department of Combinatorics & Optimization, University of Waterloo, Canada.

Citation Information: Mathematical Cryptology JMC. Volume 1, Issue 1, Pages 47–64, ISSN (Online) 1862-2984, ISSN (Print) 1862-2976, DOI: 10.1515/JMC.2007.004, May 2008

Publication History: Published Online: 28/02/2012

The HMQV protocols are 'hashed variants' of the MQV key agreement protocols. They were introduced at CRYPTO 2005 by Krawczyk, who claimed that the HMQV protocols have very significant advantages over their MQV counterparts: (i) security proofs under reasonable assumptions in the (extended) Canetti-Krawczyk model for key exchange; and (ii) superior performance in some situations.

In this paper we demonstrate that the HMQV protocols are insecure by presenting realistic attacks in the Canetti-Krawczyk model that recover a victim's static private key. We propose HMQV-1, patched versions of the HMQV protocols that resists our attacks (but do not have any performance advantages over MQV). We also identify some fallacies in the security proofs for HMQV, critique the security model, and raise some questions about the assurances that proofs in this model can provide.

Key Words: Cryptography,; key agreement protocols,; provable security

Comments (0)

Please log in or register to comment.