Provably Secure Gateway-Oriented Password-Based Authenticated Key Exchange Protocol Resistant to Password Guessing Attacks

被引:0
作者
Chien, Hung-Yu [1 ]
Wu, Tzong-Chen [2 ]
Yeh, Ming-Kuei [3 ]
机构
[1] Natl Chi Nan Univ, Dept Informat Management, Nantou 545, Taiwan
[2] Natl Taiwan Univ Sci & Technol, Dept Informat Management, Taipei 106, Taiwan
[3] Nanya Inst Technol, Dept Informat Management, Chungli 320, Taiwan
关键词
security; authentication; gateway; password guessing attack; semantic security; IMPROVEMENT; SCHEME;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A Gateway-oriented Password-based Authenticated Key Exchange (GPAKE) scheme allows a client to establish an authenticated session key with a gateway via the help of an authentication server, where the client has pre-shared a password with the server. The desirable security properties of a GPAKE include session key semantic security, key privacy against servers, and password guessing attacks resistance. Abdalla et al.'s scheme (Asiacrypt 2005) [1] proposed the first GPAKE scheme, and then Abdalla et al. [13] and Byun et al.'s [2] had respectively proposed their improvements to enhance the security. Unfortunately, we find that all the improved schemes fail to commit the security requirements. In this paper, we point out security weaknesses of the improved scheme. To enhance the security, we propose a new GPAKE scheme, and prove its security in an enhanced model.
引用
收藏
页码:249 / 265
页数:17
相关论文
共 20 条
  • [1] Abdalla M, 2005, LECT NOTES COMPUT SC, V3386, P65
  • [2] Abdalla M, 2005, LECT NOTES COMPUT SC, V3788, P566
  • [3] Abdalla M, 2008, LECT NOTES COMPUT SC, V5339, P133, DOI 10.1007/978-3-540-89641-8_10
  • [4] Bellare M, 2000, LECT NOTES COMPUT SC, V1807, P139
  • [5] Bellare M., 2005, P 27 ACM S THEOR COM, P57
  • [6] Bickford M., 2010, 6 INT VER WORKSH, P13
  • [7] Logic of authentication
    Burrows, Michael
    Abadi, Martin
    Needham, Roger
    [J]. Operating Systems Review (ACM), 1989, 23 (05): : 1 - 13
  • [8] Security analysis and improvement of a gateway-oriented password-based authenticated key exchange protocol
    Byun, Jin Wook
    Lee, Dong Hoon
    Lim, Jong In
    [J]. IEEE COMMUNICATIONS LETTERS, 2006, 10 (09) : 683 - 685
  • [9] Camenisch J, 1997, LECT NOTES COMPUT SC, V1294, P410
  • [10] A novel three-party encrypted key exchange protocol
    Chang, CC
    Chang, YF
    [J]. COMPUTER STANDARDS & INTERFACES, 2004, 26 (05) : 471 - 476