Cryptanalysis of a communication-efficient three-party password authenticated key exchange protocol

被引:26
|
作者
Wu, Shuhua [1 ,2 ]
Pu, Qiong [3 ]
Wang, Shengbao [4 ]
He, Debiao [5 ]
机构
[1] Informat Engn Univ, Dept Network Engn, Zhengzhou, Peoples R China
[2] Chinese Acad Sci, State Key Lab Informat Secur, Grad Univ, Beijing, Peoples R China
[3] Tongji Univ, CIMS Res Ctr, Shanghai 200092, Peoples R China
[4] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
[5] Wuhan Univ, Sch Math & Stat, Wuhan 430072, Peoples R China
基金
高等学校博士学科点专项科研基金; 中国国家自然科学基金; 中国博士后科学基金;
关键词
Password-based; Authenticated key exchange; Three-party; Dictionary attack; SERVER PUBLIC-KEYS; GUESSING ATTACKS; DIFFIE-HELLMAN; SECURE; AGREEMENT;
D O I
10.1016/j.ins.2012.06.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We revisit the communication-efficient three-party password authenticated key exchange protocol recently proposed by Chang et al. We show it is insecure against partition attacks, whereby the adversary can guess the correct password off-line. Thereafter we propose an enhanced protocol that can resist the attack described and yet is quite efficient. Furthermore, we prove its security in a widely accepted model. (C) 2012 Elsevier Inc. All rights reserved.
引用
收藏
页码:83 / 96
页数:14
相关论文
共 50 条