摘要
Recently, Lu and Cao published a novel protocol for password-based authenticated key exchanges (PAKE) in a three-party setting in Journal of Computers and Security, where two clients, each shares a human-memorable password with a trusted server, can construct a secure session key. They argued that their simple three-party PAKE (3-PAKE) protocol can resist against various known attacks. In this paper, we show that this protocol is vulnerable to a kind of man-in-the-middle attack that exploits an authentication flaw in their protocol and is subject to the undetectable on-line dictionary attack. We also conduct a detailed analysis on the flaws in the protocol and provide an improved protocol.
| 源语言 | 英语 |
|---|---|
| 页(从-至) | 16-21 |
| 页数 | 6 |
| 期刊 | Computers and Security |
| 卷 | 27 |
| 期 | 1-2 |
| DOI | |
| 出版状态 | 已出版 - 3月 2008 |
学术指纹
探究 'Cryptanalysis of simple three-party key exchange protocol' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver