Comments on Gateway-Oriented Password-Based Authenticated Key Exchange Protocol
Tzong‐Chen Wu, Hung‐Yu Chien
Abstract
Tzong‐Chen Wu, Hung‐Yu Chien
Abstract
A gateway-oriented password-based authenticated key exchange (GPAKE) scheme allows a client to establish an authenticated session key with a gateway via the help of an authentication server, where the client has pre-shared a password with the server. The desirable security properties of a GPAKE include session key semantic security, key privacy against the server, and password guessing attacks resistance. This letter shows that both Byun et al.'s schemes failed to commit the security requirements. The improved scheme would be proposed in the extended version.
OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
A gateway-oriented password-based authenticated key exchange (GPAKE) scheme allows a client to establish an authenticated session key with a gateway via the help of an authentication server, where the client has pre-shared a password with the server. The desirable security properties of a GPAKE include session key semantic security, key privacy against the server, and password guessing attacks resistance. This letter shows that both Byun et al.'s schemes failed to commit the security requirements. The improved scheme would be proposed in the extended version.
Key concepts: Computer science, Password, S/KEY, Authenticated Key Exchange, Computer security, One-time password, Password strength, Computer network