A Password-based Key Establishment Protocol with Symmetric Key Cryptography

被引:1
|
作者
Erguler, Imran [1 ]
Anarim, Emin [2 ]
机构
[1] TUBITAK UEKAE Gebze, Natl Res Inst Elect & Cryptol, Kocaeli, Turkey
[2] Bogazici Univ, Elect Elect Engn Dept, Istanbul, Turkey
来源
2008 4TH IEEE INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB) | 2008年
关键词
D O I
10.1109/WiMob.2008.112
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In 2005, Laih, Ding and Huang proposed a password-based key establishment protocol such that a user and a server can authenticate each other and generate a strong session key by their shared weak password within a symmetric cipher in an insecure channel. In this protocol, a special function which is a combination of a picture function and a distortion function e. g. CAPTCHA, is combined to authenticate the user and protect the password from the dictionary attacks that are major threats for most of the weak password-based protocols. They claim that the proposed protocol is secure against some well known attacks. However Tang and Mitchell show that the protocol suffers from an offline dictionary attack requiring a machine-based search of size 2(23) which takes only about 2.3 hours. So designing such a protocol with providing practical security against offline attack is still an open problem. In this study, we introduce two password-based authenticated key establishment protocols that provide practical security against offline dictionary attacks by only using symmetric key cryptography.
引用
收藏
页码:543 / 548
页数:6
相关论文
共 50 条
  • [21] Efficient augmented password-based encrypted key exchange protocol
    Wu, Shuhua
    Zhu, Yuefei
    MOBILE AD-HOC AND SENSOR NETWORKS, PROCEEDINGS, 2006, 4325 : 533 - +
  • [22] Structured and efficient password-based group key agreement protocol
    Zhu, Hongfeng, 1600, Ubiquitous International (05):
  • [23] Efficient and secure password-based authenticated key exchange protocol
    Wu, Shuhua
    Zhu, Yuefei
    2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 1269 - 1272
  • [24] Efficient password-based authenticated group key exchange protocol
    School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu 610054, China
    不详
    Dianzi Keji Diaxue Xuebao, 2009, 3 (393-396+414):
  • [25] Password-based tripartite key exchange protocol with forward secrecy
    Li, Guomin
    He, Dake
    Guo, Wei
    ROUGH SETS AND KNOWLEDGE TECHNOLOGY, 2008, 5009 : 731 - 738
  • [26] Simple and efficient password-based authenticated key exchange protocol
    Wang L.-B.
    Pan J.-X.
    Ma C.-S.
    Journal of Shanghai Jiaotong University (Science), 2011, 16 (4) : 459 - 465
  • [27] Password-Based Authenticated Key Exchange
    Pointcheval, David
    PUBLIC KEY CRYPTOGRAPHY - PKC 2012, 2012, 7293 : 390 - 397
  • [28] A simple three-party password-based key exchange protocol
    Huang, Hui-Feng
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2009, 22 (07) : 857 - 862
  • [29] On a simple three-party password-based key exchange protocol'
    Lin, Ching-Ying
    Hwang, Tzonelih
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2011, 24 (11) : 1520 - 1532
  • [30] Universally Composable Three Party Password-based Key Exchange Protocol
    Deng Miaolei
    Ma Jianfeng
    Le Fulong
    CHINA COMMUNICATIONS, 2009, 6 (03) : 150 - 155