<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-014-03-0416</article-id>
      <article-id pub-id-type="publisher-id">28955</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>E.3 - DATA ENCRYPTION</subject>
          <subject>H.1.1 - Systems and Information Theory</subject>
          <subject>H.4.3 - Communications Applications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Bilateral Unknown Key-Share Attacks in Key Agreement Protocols</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Chen</surname>
            <given-names>Liqun</given-names>
          </name>
          <email xlink:type="simple">liqun.chen@hp.com</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Tang</surname>
            <given-names>Qiang</given-names>
          </name>
          <xref ref-type="aff" rid="A2">2</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">Hewlett-Packard Laboratories, Bristol, United Kingdom</addr-line>
        <institution>Hewlett-Packard Laboratories</institution>
        <addr-line content-type="city">Bristol</addr-line>
        <country>United Kingdom</country>
      </aff>
      <aff id="A2">
        <label>2</label>
        <addr-line content-type="verbatim">École Normale Supérieure, Paris, France</addr-line>
        <institution>École Normale Supérieure</institution>
        <addr-line content-type="city">Paris</addr-line>
        <country>France</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Liqun Chen (<email xlink:type="simple">liqun.chen@hp.com</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2008</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>01</day>
        <month>02</month>
        <year>2008</year>
      </pub-date>
      <volume>14</volume>
      <issue>3</issue>
      <fpage>416</fpage>
      <lpage>440</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/6A5C9924-C622-5740-90E5-493B9EC0B2F2">6A5C9924-C622-5740-90E5-493B9EC0B2F2</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/7000108">7000108</uri>
      <permissions>
        <copyright-statement>Liqun Chen, Qiang Tang</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>Unknown Key-Share (UKS) resilience is a basic security attribute in authenticated key agreement protocols. In this paper we revisit the definitions of this attribute and the method of proving this attribute under the Bellare-Rogaway (BR) model in the literature. We propose a new type of UKS attack, which coerces two entities A and B into sharing a key with each other but in fact A thinks that he is sharing the key with another entity C and B thinks that he is sharing the key with another entity D, where C and D might or might not be the same entity. We call this attack a Bilateral Unknown Key-Share (BUKS) attack. We demonstrate that a few well-known authenticated key agreement protocols are vulnerable to this attack. We then explore a gap between the conventional BR-type proof and a BUKS adversary's behavior, and extend the BR model to cover the BUKS resilience attribute. At the end of the paper, we provide a general countermeasure and its security proof under the extended model and the assumption that a collision-resistance function exists.</p>
      </abstract>
    </article-meta>
  </front>
</article>
