{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:45:02Z","timestamp":1783615502012,"version":"3.55.0"},"publisher-location":"Berlin, Heidelberg","reference-count":32,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783540656449","type":"print"},{"value":"9783540491620","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[1999]]},"DOI":"10.1007\/3-540-49162-7_12","type":"book-chapter","created":{"date-parts":[[2007,7,31]],"date-time":"2007-07-31T23:51:55Z","timestamp":1185925915000},"page":"154-170","source":"Crossref","is-referenced-by-count":113,"title":["Unknown Key-Share Attacks on the Station-to-Station (STS) Protocol"],"prefix":"10.1007","author":[{"given":"Simon","family":"Blake-Wilson","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alfred","family":"Menezes","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[1999,10,29]]},"reference":[{"key":"12_CR1","unstructured":"ANSI X9.30 (Part 1), Public Key Cryptography Using Irreversible Algorithms for the Financial Services Industry-Part 1: The Digital Signature Algorithm (DSA), 1995."},{"key":"12_CR2","unstructured":"ANSI X9.31, Digital Signatures Using Reversible Public Key Cryptography for the Financial Services Industry (rDSA), working draft, March 1998."},{"key":"12_CR3","unstructured":"ANSI X9.62, The Elliptic Curve Digital Signature Algorithm (ECDSA), working draft, August 1998."},{"key":"12_CR4","unstructured":"ANSI X9.63, Elliptic Curve Key Agreement and Key Transport Protocols, working draft, October 1998."},{"key":"12_CR5","doi-asserted-by":"crossref","unstructured":"M. Bellare, R. Canetti and H. Krawczyk, \u201cA modular approach to the design and analysis of authentication and key exchange protocols\u201d, Proceedings of the 30th Annual Symposium on the Theory of Computing, 1998. A full version of this paper is available at https:\/\/2.zoppoz.workers.dev:443\/http\/www-cse.ucsd.edu\/users\/mihir","DOI":"10.1145\/276698.276854"},{"key":"12_CR6","doi-asserted-by":"crossref","unstructured":"M. Bellare and P. Rogaway, \u201cRandom oracles are practical: a paradigm for designing efficient protocols\u201d, 1st ACM Conference on Computer and Communications Security, 1993, 62\u201373. A full version of this paper is available at https:\/\/2.zoppoz.workers.dev:443\/http\/www-cse.ucsd.edu\/users\/mihir","DOI":"10.1145\/168588.168596"},{"key":"12_CR7","series-title":"Lect Notes Comput Sci","first-page":"232","volume-title":"Advances in Cryptology-Crypto\u2019 93","author":"M. Bellare","year":"1993","unstructured":"M. Bellare and P. Rogaway, \u201cEntity authentication and key distribution\u201d, Advances in Cryptology-Crypto\u2019 93, LNCS 773, 1993, 232\u2013249. A full version of this paper is available at https:\/\/2.zoppoz.workers.dev:443\/http\/www-cse.ucsd.edu\/users\/mihir"},{"key":"12_CR8","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1007\/3-540-68339-9_34","volume-title":"Advances in Cryptology-Eurocrypt\u2019 96","author":"M. Bellare","year":"1996","unstructured":"M. Bellare and P. Rogaway, \u201cThe exact security of digital signatures\u2014how to sign with RSA and Rabin\u201d, Advances in Cryptology-Eurocrypt\u2019 96, LNCS 1070, 1996, 399\u2013416."},{"key":"12_CR9","series-title":"Lect Notes Comput Sci","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1007\/BFb0024447","volume-title":"Proceedings of the sixth IMA International Conference on Cryptography and Coding","author":"S. Blake-Wilson","year":"1997","unstructured":"S. Blake-Wilson, D. Johnson and A. Menezes, \u201cKey agreement protocols and their security analysis\u201d, Proceedings of the sixth IMA International Conference on Cryptography and Coding, LNCS 1355, 1997, 30\u201345. A full version of this paper is available at https:\/\/2.zoppoz.workers.dev:443\/http\/www.cacr.math.uwaterloo.ca\/"},{"key":"12_CR10","series-title":"Lect Notes Comput Sci","volume-title":"Proceedings of SAC\u2019 98","author":"S. Blake-Wilson","year":"1998","unstructured":"S. Blake-Wilson and A. Menezes, \u201cAuthenticated Diffie-Hellman key agreement protocols\u201d, Proceedings of SAC\u2019 98, LNCS, to appear."},{"key":"12_CR11","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/BF00124891","volume":"2","author":"W. Diffie","year":"1992","unstructured":"W. Diffie, P. vanOorschot and M. Wiener, \u201cAuthentication and authenticated key exchanges\u201d, Designs, Codes and Cryptography, 2 (1992), 107\u2013125.","journal-title":"Designs, Codes and Cryptography"},{"key":"12_CR12","doi-asserted-by":"publisher","first-page":"469","DOI":"10.1109\/TIT.1985.1057074","volume":"31","author":"T. ElGamal","year":"1985","unstructured":"T. ElGamal, \u201cA public key cryptosystem and a signature scheme based on discrete logarithms\u201d, IEEE Transactions on Information Theory, 31 (1985), 469\u2013472.","journal-title":"IEEE Transactions on Information Theory"},{"key":"12_CR13","doi-asserted-by":"publisher","first-page":"281","DOI":"10.1137\/0217017","volume":"17","author":"S. Goldwasser","year":"1988","unstructured":"S. Goldwasser, S. Micali, and R. Rivest, \u201cA digital signature scheme secure against adaptive chosen message attacks\u201d, SIAM Journal on Computing, 17 (1988), 281\u2013308.","journal-title":"SIAM Journal on Computing"},{"key":"12_CR14","unstructured":"IPSEC Working Group, The OAKLEY Key Determination Protocol, Internet Draft, Internet Engineering Task Force, available from https:\/\/2.zoppoz.workers.dev:443\/http\/www.ietf.cnri.reston.va.us\/"},{"key":"12_CR15","unstructured":"ISO\/IEC 8824-1, Information Technology-Open Systems Interconnection-Abstract Syntax Notation One (ANS.1)-Part 1: Specification of Basic Notation."},{"key":"12_CR16","unstructured":"ISO\/IEC 8825-3, Information Technology-Open Systems Interconnection-Specification of ASN.1 Encoding Rules-Part 3: Distinguished Canonical Encoding Rules."},{"key":"12_CR17","unstructured":"ISO\/IEC 9798-3, Information Technology-Security Techniques-Entity Authentication Mechanisms-Part 3: Entity Authentication Using a Public-Key Algorithm 1993."},{"key":"12_CR18","unstructured":"ISO\/IEC 11770-3, Information Technology-Security Techniques-Key Management-Part 3: Mechanisms Using Asymmetric Techniques, draft, (DIS), 1996."},{"key":"12_CR19","unstructured":"D. Johnson, Contribution to ANSI X9F1 working group, 1997."},{"key":"12_CR20","unstructured":"B. Kaliski, Contribution to ANSI X9F1 and IEEE P1363 working groups, June 17 1998."},{"key":"12_CR21","unstructured":"L. Law, A. Menezes, M. Qu, J. Solinas, S. Vanstone, \u201cAn efficient protocol for authenticated key agreement\u201d, Technical report CORR 98-05, Department of C&O, University of Waterloo, 1998. Also available at https:\/\/2.zoppoz.workers.dev:443\/http\/www.cacr.math.uwaterloo.ca\/"},{"key":"12_CR22","doi-asserted-by":"publisher","first-page":"649","DOI":"10.2307\/1971363","volume":"126","author":"H.W. Lenstra","year":"1987","unstructured":"H.W. Lenstra, \u201cFactoring integers with elliptic curves\u201d, Annals of Mathematics, 126 (1987), 649\u2013673.","journal-title":"Annals of Mathematics"},{"key":"12_CR23","series-title":"Lect Notes Comput Sci","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/BFb0052240","volume-title":"Advances in Cryptology-Crypto\u2019 97","author":"C. Lim","year":"1997","unstructured":"C. Lim and P. Lee, \u201cA key recovery attack on discrete log-based schemes using a prime order subgroup\u201d, Advances in Cryptology-Crypto\u2019 97, LNCS 1294, 1997, 249\u2013263."},{"key":"12_CR24","unstructured":"A. Menezes, M. Qu and S. Vanstone, \u201cSome new key agreement protocols providing mutual implicit authentication\u201d, Workshop on Selected Areas in Cryptography (SAC\u2019 95), 22\u201332, 1995."},{"key":"12_CR25","unstructured":"A. Menezes, P. van Oorschot and S. Vanstone, Handbook of Applied Cryptography, CRC Press, 1997."},{"key":"12_CR26","first-page":"23","volume":"2","author":"C. Mitchell","year":"1993","unstructured":"C. Mitchell and A. Thomas, \u201cStandardising authentication protocols based on public key techniques\u201d, Journal of Computer Security, 2 (1993), 23\u201336.","journal-title":"Journal of Computer Security"},{"key":"12_CR27","unstructured":"National Institute of Standards and Technology, Digital Signature Standard, FIPS Publication 186, 1994."},{"key":"12_CR28","unstructured":"National Institute of Standards and Technology, Secure Hash Standard (SHS), FIPS Publication 180-1, 1995."},{"key":"12_CR29","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1109\/TIT.1978.1055817","volume":"24","author":"S. Pohlig","year":"1978","unstructured":"S. Pohlig and M. Hellman, \u201cAn improved algorithm for computing logarithms over GF(p) and its cryptographic significance\u201d, IEEE Transactions on Information Theory, 24 (1978), 106\u2013110.","journal-title":"IEEE Transactions on Information Theory"},{"key":"12_CR30","unstructured":"M.O. Rabin, \u201cDigitalized signatures and public-key functions as intractable as factorization\u201d, MIT\/LCS\/TR-212, MIT Laboratory for Computer Science, 1979."},{"key":"12_CR31","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/359340.359342","volume":"21","author":"R.L. Rivest","year":"1978","unstructured":"R.L. Rivest, A. Shamir and L.M. Adleman, \u201cA method for obtaining digital signatures and public-key cryptosystems\u201d, Communications of the ACM, 21 (1978), 120\u2013126.","journal-title":"Communications of the ACM"},{"key":"12_CR32","doi-asserted-by":"crossref","unstructured":"P. van Oorschot, \u201cExtending cryptographic logics of belief to key agreement protocols\u201d, 1st ACM Conference on Computer and Communications Security, ACM Press, 1993, 232\u2013243.","DOI":"10.1145\/168588.168617"}],"container-title":["Lecture Notes in Computer Science","Public Key Cryptography"],"original-title":[],"link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/content\/pdf\/10.1007\/3-540-49162-7_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,1]],"date-time":"2019-05-01T16:22:44Z","timestamp":1556727764000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/link.springer.com\/10.1007\/3-540-49162-7_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[1999]]},"ISBN":["9783540656449","9783540491620"],"references-count":32,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/3-540-49162-7_12","relation":{},"ISSN":["0302-9743"],"issn-type":[{"value":"0302-9743","type":"print"}],"subject":[],"published":{"date-parts":[[1999]]}}}