Enhanced password-based simple three-party key exchange protocol

  • Kim, Hyun-Seok
  • Choi, Jin-Young
Citations

WEB OF SCIENCE

38
Citations

SCOPUS

54

초록

Recently, Lu and Cao proposed a simple three-party password-based key exchange (STPKE) protocol based on the CCDH assumption. They claimed that their protocol is secure, efficient, and practical. In this paper, unlike their claims, we find that the STPKE protocol is still vulnerable to undetectable on-line password guessing attacks by using formal description, BPR model. These weakness is due to the fact that the messages of the communicants are not appropriately encrypted into the exchanged cryptographic messages. To enhance the security of the STPKE protocol, we suggest a countermeasure to resist our described attacks while the merits of the original protocol are left unchanged. (C) 2008 Elsevier Ltd. All rights reserved.

키워드

Password-based key exchange protocolUndetectable on-line guessing attackBPR modelSECUREAGREEMENT
제목
Enhanced password-based simple three-party key exchange protocol
저자
Kim, Hyun-SeokChoi, Jin-Young
DOI
10.1016/j.compeleceng.2008.05.007
발행일
2009-01
유형
Article
저널명
Computers and Electrical Engineering
35
1
페이지
107 ~ 114