Cross-Domain Password-Based Authenticated Key Exchange Revisited

被引:0
|
作者
Chen, Liqun [1 ]
Lim, Hoon Wei [2 ]
Yang, Guomin [3 ]
机构
[1] HP Labs, Bristol, Avon, England
[2] Nanyang Technol Univ, Singapore, Singapore
[3] Univ Wollongong, Wollongong, NSW, Australia
关键词
Password-based protocol; key exchange; cross-domain; client-to-client; SECURE; CRYPTANALYSIS; PROTOCOL; CLIENTS;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We revisit the problem of cross-domain secure communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a four-party password-based authenticated key exchange (4PAKE) protocol that takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that "certify" some key materials that the users can subsequently exchange and agree on a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange protocol and two-party asymmetric-key based key exchange protocol as black boxes, we combine them to obtain a generic and provably secure 4PAKE protocol.
引用
收藏
页码:1052 / 1060
页数:9
相关论文
共 50 条
  • [41] A Generic Construction of Tightly Secure Password-Based Authenticated Key Exchange
    Pan, Jiaxin
    Zeng, Runzhi
    ADVANCES IN CRYPTOLOGY, ASIACRYPT 2023, PT VIII, 2023, 14445 : 143 - 175
  • [42] On password-based authenticated key exchange using collisionful hash functions
    Bakhtiari, S
    Safavi-Naini, R
    Pieprzyk, J
    INFORMATION SECURITY AND PRIVACY: 1ST AUSTRALASIAN CONFERENCE, ACISP 96, 1996, 1172 : 299 - 310
  • [43] Partitioned Group Password-based Authenticated Key Exchange with Privacy Protection
    Zhu, Hongfeng
    Zhang, Yuanle
    Wang, Xueying
    Wang, Liwei
    International Journal of Network Security, 2021, 23 (01) : 116 - 125
  • [44] Password-based authenticated key exchange in the three-party setting
    Abdalla, M
    Fouque, PA
    Pointcheval, D
    PUBLIC KEY CRYPTOGRAPHY - PKC 2005, 2005, 3386 : 65 - 84
  • [45] Password-based Authenticated Key Exchange Scheme Using Smart Card
    Liu Hui
    Zhong Shaojun
    FIFTH INTERNATIONAL CONFERENCE ON MACHINE VISION (ICMV 2012): COMPUTER VISION, IMAGE ANALYSIS AND PROCESSING, 2013, 8783
  • [46] Password-Based Authenticated Key Exchange from Standard Isogeny Assumptions
    Terada, Shintaro
    Yoneyama, Kazuki
    PROVABLE SECURITY, PROVSEC 2019, 2019, 11821 : 41 - 56
  • [47] Efficient three-party password-based authenticated key exchange protocol
    Xu, C.-X., 1600, Univ. of Electronic Science and Technology of China (41):
  • [48] Enhancements of a Three-Party Password-Based Authenticated Key Exchange Protocol
    Wu, Shuhua
    Chen, Kefei
    Zhu, Yuefei
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2013, 10 (03) : 215 - 221
  • [49] A General Construction for Password-Based Authenticated Key Exchange from Witness PRFs
    Nan, Jiehui
    Zheng, Mengce
    Wang, Zilong
    Hu, Honggang
    FRONTIERS IN CYBER SECURITY, FCS 2019, 2019, 1105 : 253 - 267
  • [50] Cryptanalysis of Server-Aided Password-Based Authenticated Key Exchange Protocols
    Nam, Junghyun
    Choo, Kim-Kwang Raymond
    Paik, Juryon
    Won, Dongho
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (02): : 47 - 57