Cryptanalysis of authenticated key exchange 3P-EKE protocol and its enhancement
Archana Raghuvamshi, P. Venkateshwara Rao, P. Premchand
Abstract
Archana Raghuvamshi, P. Venkateshwara Rao, P. Premchand
Abstract
Key Agreement or key exchange algorithm proposed by Diffie-Hellman in 1976 has suffered from man-in-middle attack. In 2002, Zhu et al. proposed a password authenticated key exchange protocol based on RSA. Later, Yeh et al. has shown that Zhu et al.'s protocol suffers from the undetectable password-guessing attacks and also has given solutions for improvement. Recently, Chang and Chang proposed a novel three party simple key exchange protocol. Later, Yoon and Yoo presented an Undetectable online password guessing attack on the above protocol. Recently, a password key exchange protocol PSRJ was proposed and also claimed to be in-vulnerable to Undetectable online password guessing attack proposed by Yoon and Yoo. This paper presents a Detectable on-line password guessing attack on PSRJ protocol. Additionally, to overcome the attack, an enhancement over the existing protocol with Exclusive OR operations are proposed.
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Key Agreement or key exchange algorithm proposed by Diffie-Hellman in 1976 has suffered from man-in-middle attack. In 2002, Zhu et al. proposed a password authenticated key exchange protocol based on RSA. Later, Yeh et al. has shown that Zhu et al.'s protocol suffers from the undetectable password-guessing attacks and also has given solutions for improvement. Recently, Chang and Chang proposed a novel three party simple key exchange protocol. Later, Yoon and Yoo presented an Undetectable online password guessing attack on the above protocol. Recently, a password key exchange protocol PSRJ was proposed and also claimed to be in-vulnerable to Undetectable online password guessing attack proposed by Yoon and Yoo. This paper presents a Detectable on-line password guessing attack on PSRJ protocol. Additionally, to overcome the attack, an enhancement over the existing protocol with Exclusive OR operations are proposed.
Key concepts: Password, Zero-knowledge password proof, Computer science, Key exchange, S/KEY, Authenticated Key Exchange, Password strength, Oakley protocol