2010•Unpublished venueRequires access

Password-based authenticated key exchange protocols

Yuanyuan Su, Wengang Li

Open publisher page 1 citations

Abstract

the two-party password-based key exchange protocol (PAKE) is the protocol in which two communications entities can authenticate each other and establish a session key over an insecure network. Designing a secure PAKE protocols is non-trivial than one may appear at first glance since the password is picked up by users from a small space, and therefore the protocol is vulnerable to dictionary attacks because an adversary can enumerate all possible passwords in an attempt to determine the correct one. So A secure PAKE protocol should be resisted to such dictionary attacks. In gerneraly, offline dictionary attacks present more difficult to resist than online dictionary attacks. That is, When a PAKE is said to be secure, it can not be break by offline dictionary attracks. Althought a lot of secure definitions and models of PAKE over pass ten yeas are proposed, however, the power of adversay in this model is limited so that the model can not well captued more realistic attacks in practice. In this paper, we extend existing PAKE definition to a new one so that improved model can give an adversary more power to break the protocols.

About this research paper

What this paper is about

the two-party password-based key exchange protocol (PAKE) is the protocol in which two communications entities can authenticate each other and establish a session key over an insecure network. Designing a secure PAKE protocols is non-trivial than one may appear at first glance since the password is picked up by users from a small space, and therefore the protocol is vulnerable to dictionary attacks because an adversary can enumerate all possible passwords in an attempt to determine the correct one. So A secure PAKE protocol should be resisted to such dictionary attacks. In gerneraly, offline dictionary attacks present more difficult to resist than online dictionary attacks. That is, When a PAKE is said to be secure, it can not be break by offline dictionary attracks. Althought a lot of secure definitions and models of PAKE over pass ten yeas are proposed, however, the power of adversay in this model is limited so that the model can not well captued more realistic attacks in practice. In this paper, we extend existing PAKE definition to a new one so that improved model can give an adversary more power to break the protocols.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

the two-party password-based key exchange protocol (PAKE) is the protocol in which two communications entities can authenticate each other and establish a session key over an insecure network. Designing a secure PAKE protocols is non-trivial than one may appear at first glance since the password is picked up by users from a small space, and therefore the protocol is vulnerable to dictionary attacks because an adversary can enumerate all possible passwords in an attempt to determine the correct one. So A secure PAKE protocol should be resisted to such dictionary attacks. In gerneraly, offline dictionary attacks present more difficult to resist than online dictionary attacks. That is, When a PAKE is said to be secure, it can not be break by offline dictionary attracks. Althought a lot of secure definitions and models of PAKE over pass ten yeas are proposed, however, the power of adversay in this model is limited so that the model can not well captued more realistic attacks in practice. In this paper, we extend existing PAKE definition to a new one so that improved model can give an adversary more power to break the protocols.

Key concepts: Authenticated Key Exchange, Password, Dictionary attack, Computer science, Adversary, Computer security, Protocol (science), Session (web analytics)

Related papers

Back to paper searchBrowse research topicsOriginal source
Password-based authenticated key exchange protocols — Research Paper | ScholarLens