2011•Procedia EngineeringOpen access

Offline dictionary attack on a universally composable three-party password-based key exchange protocol

Wei Yuan, Liang Qing Hu, Hongtu Li, Jianfeng Chu

Open full text 4 citations

Abstract

Key exchange protocols are fundamental for establishing secure communication channels over public networks. Password-based key exchange protocols allow parties to share a secret key in an authentic manner based on an easily memorizable password. Recently, Deng et al. proposed a three-party password-based key exchange protocol in the universal composable framework in China Communications, where two users, each one of whom shares a human-memorable password with a trusted server, can authenticate each other and compute a secure session key. In this letter, we show that Deng et al.’s protocol is insecure against offline dictionary attack by any other client. Hence, the protocol doesn’t achieve their aim.

Open-access reader

About this research paper

What this paper is about

Key exchange protocols are fundamental for establishing secure communication channels over public networks. Password-based key exchange protocols allow parties to share a secret key in an authentic manner based on an easily memorizable password. Recently, Deng et al. proposed a three-party password-based key exchange protocol in the universal composable framework in China Communications, where two users, each one of whom shares a human-memorable password with a trusted server, can authenticate each other and compute a secure session key. In this letter, we show that Deng et al.’s protocol is insecure against offline dictionary attack by any other client. Hence, the protocol doesn’t achieve their aim.

Why it matters

OpenAlex reports 4 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Key exchange protocols are fundamental for establishing secure communication channels over public networks. Password-based key exchange protocols allow parties to share a secret key in an authentic manner based on an easily memorizable password. Recently, Deng et al. proposed a three-party password-based key exchange protocol in the universal composable framework in China Communications, where two users, each one of whom shares a human-memorable password with a trusted server, can authenticate each other and compute a secure session key. In this letter, we show that Deng et al.’s protocol is insecure against offline dictionary attack by any other client. Hence, the protocol doesn’t achieve their aim.

Key concepts: Password, S/KEY, Key exchange, Computer science, Computer security, Zero-knowledge password proof, Authenticated Key Exchange, Key (lock)

Related papers

Back to paper searchBrowse research topicsOriginal source
Offline dictionary attack on a universally composable three-party password-based key exchange protocol — Research Paper | ScholarLens