Offline dictionary attack on a universally composable three-party password-based key exchange protocol
Wei Yuan, Liang Qing Hu, Hongtu Li, Jianfeng Chu
Abstract
Open-access reader
Wei Yuan, Liang Qing Hu, Hongtu Li, Jianfeng Chu
Abstract
Open-access reader
Key exchange protocols are fundamental for establishing secure communication channels over public networks. Password-based key exchange protocols allow parties to share a secret key in an authentic manner based on an easily memorizable password. Recently, Deng et al. proposed a three-party password-based key exchange protocol in the universal composable framework in China Communications, where two users, each one of whom shares a human-memorable password with a trusted server, can authenticate each other and compute a secure session key. In this letter, we show that Deng et al.’s protocol is insecure against offline dictionary attack by any other client. Hence, the protocol doesn’t achieve their aim.
OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Key exchange protocols are fundamental for establishing secure communication channels over public networks. Password-based key exchange protocols allow parties to share a secret key in an authentic manner based on an easily memorizable password. Recently, Deng et al. proposed a three-party password-based key exchange protocol in the universal composable framework in China Communications, where two users, each one of whom shares a human-memorable password with a trusted server, can authenticate each other and compute a secure session key. In this letter, we show that Deng et al.’s protocol is insecure against offline dictionary attack by any other client. Hence, the protocol doesn’t achieve their aim.
Key concepts: Password, S/KEY, Key exchange, Computer science, Computer security, Zero-knowledge password proof, Authenticated Key Exchange, Key (lock)