arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.31519cs.CRcs.NI

WPA3快速且安全的对等实体同时认证

Fast and Secure Simultaneous Authentication of Equals for WPA3

João Ferreira, André Zúquete, Hélder Gomes

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出一种改进SAE协议的架构,通过非对称资源成本模型、慢路径密钥推导和票据机制,减轻WPA3中AP的DoS风险,同时保持合法访问。

中文摘要 AI 辅助

WPA3中引入的对等实体同时认证(SAE)协议,为网络预共享密钥(PSK)提供了针对离线字典攻击的强健保护,同时也保护会话密钥免受其他知晓该PSK的人的攻击。然而,其在密码元素(PE)推导上的高计算成本使得接入点(AP)容易受到CPU耗尽型拒绝服务(DoS)攻击。本文提出了一种对SAE的弹性架构修改。首先,我们引入了一种非对称资源成本模型,将密码元素的迭代发现卸载到客户端,使得AP在握手期间保持固定的计算负载。为进一步缓解暴力破解尝试,我们实现了一种基于慢路径密钥推导的机制(使用可变成本密钥推导函数,如PBKDF2或Argon2),在请求方中引入有意的处理延迟。最后,我们引入了一种基于票据的机制,以促进已知设备的高效重新认证,绕过昂贵的交换,同时在对抗条件下保持系统可用性。实验结果表明,该架构显著降低了DoS风险,且不影响合法网络访问。

英文摘要

The Simultaneous Authentication of Equals (SAE) protocol, introduced in WPA3, provides robust protection against offline dictionary attacks against a network Pre-Shared Key (PSK) and also protection of session keys from other people knowing that PSK. However, its high computational cost for the Password Element (PE) derivation makes Access Points (APs) vulnerable to CPU exhaustion Denial-of-Service (DoS) attacks. This paper proposes a resilient architectural modification to SAE. First, we introduce an asymmetric resource cost model that offloads the iterative discovery of cryptographic elements to the client, allowing the AP to maintain a fixed computational load during the handshake. To further mitigate brute-force attempts, we implement a mechanism based on a slow-path key derivation (with variable cost key derivation functions, such as PBKDF2 or Argon2), incorporating a deliberate processing delay on the supplicant. Finally, we introduce a ticket-based mechanism to facilitate efficient re-authentication for known devices, bypassing expensive exchanges while preserving system availability under adversarial conditions. Experimental results demonstrate that this architecture significantly mitigates DoS risks without compromising legitimate network access.

发表机构

  • University of Aveiro(阿威罗大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑