2012Information Technology And ControlOpen access

SECURITY ENHANCEMENT ON SIMPLE THREE PARTY PAKE PROTOCOL

Shirisha Tallapally

Open full text 14 citations

Abstract

In the field of cryptography, the three-party authenticated key exchange protocol is an important tool, especially in the secure communication areas. In this protocol, two clients share a human-memorable password with a trusted server whereby the two clients receive a secure session key. Most recently, Huang proposed a simple and efficient three party password-based key exchange protocol. She claimed that the proposed protocol is secure against various attacks. However, Yoon and Yoo proved an undetectable online password guessing attack on Huang’s protocol. In the present paper, an unknown key share attack on Huang’s three party PAKE protocol using undetectable online password guessing attack is demonstrated. Additionally, an alternative protocol that eliminates this attack is proposed. Moreover, the proposed protocol requires only four message transmission rounds.DOI: http://dx.doi.org/10.5755/j01.itc.41.1.842

Open-access reader

About this research paper

What this paper is about

In the field of cryptography, the three-party authenticated key exchange protocol is an important tool, especially in the secure communication areas. In this protocol, two clients share a human-memorable password with a trusted server whereby the two clients receive a secure session key. Most recently, Huang proposed a simple and efficient three party password-based key exchange protocol. She claimed that the proposed protocol is secure against various attacks. However, Yoon and Yoo proved an undetectable online password guessing attack on Huang’s protocol. In the present paper, an unknown key share attack on Huang’s three party PAKE protocol using undetectable online password guessing attack is demonstrated. Additionally, an alternative protocol that eliminates this attack is proposed. Moreover, the proposed protocol requires only four message transmission rounds.DOI: http://dx.doi.org/10.5755/j01.itc.41.1.842

Why it matters

OpenAlex reports 14 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In the field of cryptography, the three-party authenticated key exchange protocol is an important tool, especially in the secure communication areas. In this protocol, two clients share a human-memorable password with a trusted server whereby the two clients receive a secure session key. Most recently, Huang proposed a simple and efficient three party password-based key exchange protocol. She claimed that the proposed protocol is secure against various attacks. However, Yoon and Yoo proved an undetectable online password guessing attack on Huang’s protocol. In the present paper, an unknown key share attack on Huang’s three party PAKE protocol using undetectable online password guessing attack is demonstrated. Additionally, an alternative protocol that eliminates this attack is proposed. Moreover, the proposed protocol requires only four message transmission rounds.DOI: http://dx.doi.org/10.5755/j01.itc.41.1.842

Key concepts: Computer science, Password, Computer security, Oakley protocol, Key exchange, Authenticated Key Exchange, S/KEY, Password cracking

Related papers

Back to paper searchBrowse research topicsOriginal source
SECURITY ENHANCEMENT ON SIMPLE THREE PARTY PAKE PROTOCOL — Research Paper | ScholarLens