A three-party password-based authenticated key exchange (PAKE) protocol allows two clients registered with a trusted server to generate a common cryptographic key from their individual passwords shared only with the server. A key requirement for three-party PAKE protocols is to prevent an adversary from mounting a dictionary attack. This requirement must be met even when the adversary is a malicious (registered) client who can set up normal protocol sessions with other clients. This work revisits three existing three-party PAKE protocols, namely, Guo et al.'s (2008) protocol, Huang's (2009) protocol, and Lee and Hwang's (2010) protocol, and demonstrates that these protocols are not secure against offline and/or (undetectable) online dictionary attacks in the presence of a malicious client. The offline dictionary attack we present against Guo et al.'s protocol also applies to other similar protocols including Lee and Hwang's protocol. We conclude with some suggestions on how to design a three-party PAKE protocol that is resistant against dictionary attacks
机构:Tongji Univ, Urban Mass Transit Railway Res Inst, Shanghai 201804, Peoples R China
Liang, Haiquan
Hu, Jingtai
论文数: 0引用数: 0
h-index: 0
机构:
Tongji Univ, Urban Mass Transit Railway Res Inst, Shanghai 201804, Peoples R ChinaTongji Univ, Urban Mass Transit Railway Res Inst, Shanghai 201804, Peoples R China
Hu, Jingtai
Wu, Shuhua
论文数: 0引用数: 0
h-index: 0
机构:Tongji Univ, Urban Mass Transit Railway Res Inst, Shanghai 201804, Peoples R China
机构:
Department of Information Management, National Taiwan University of Science and TechnologyDepartment of Information Management, National Taiwan University of Science and Technology
Lo N.-W.
Yeh K.-H.
论文数: 0引用数: 0
h-index: 0
机构:
Department of Information Management, Chinese Culture UniversityDepartment of Information Management, National Taiwan University of Science and Technology
机构:
Department of Information Management, National Taiwan University of Science and TechnologyDepartment of Information Management, National Taiwan University of Science and Technology
罗乃维
叶国晖
论文数: 0引用数: 0
h-index: 0
机构:
Department of Information Management, Chinese Culture UniversityDepartment of Information Management, National Taiwan University of Science and Technology
机构:
Fu Jen Catholic Univ, Dept Lib & Informat Sci, New Taipei City 24205, Taiwan
Asia Univ, Dept Photon & Commun Engn, Taichung 402, TaiwanFu Jen Catholic Univ, Dept Lib & Informat Sci, New Taipei City 24205, Taiwan
Lee, Cheng-Chi
Li, Chun-Ta
论文数: 0引用数: 0
h-index: 0
机构:
Tainan Univ Technol, Dept Informat Management, Tainan 710, TaiwanFu Jen Catholic Univ, Dept Lib & Informat Sci, New Taipei City 24205, Taiwan
Li, Chun-Ta
Hsu, Che-Wei
论文数: 0引用数: 0
h-index: 0
机构:
Fu Jen Catholic Univ, Dept Lib & Informat Sci, New Taipei City 24205, TaiwanFu Jen Catholic Univ, Dept Lib & Informat Sci, New Taipei City 24205, Taiwan