Security Analysis of Authenticated Key Exchange Protocol Based on Password
Li Li
Abstract
Li Li
Abstract
This paper gives a formal analysis on the authenticated key exchange protocol based on password using the theory of the strand space model.We introduce the ability on modeling the DH problem and the guessing attack,and then give a proof on secrecy of the password,authentication and the secrecy of the session key of the simplified DH-EKE protocol.Based on the analysis,we propose a basic condition of the key exchange protocol based on password on resisting the guessing attack.Extending the method to the three-party case,a necessary condition is concluded to guarantee the security of the three-party authenticated key exchange protocol based on the pure password.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
This paper gives a formal analysis on the authenticated key exchange protocol based on password using the theory of the strand space model.We introduce the ability on modeling the DH problem and the guessing attack,and then give a proof on secrecy of the password,authentication and the secrecy of the session key of the simplified DH-EKE protocol.Based on the analysis,we propose a basic condition of the key exchange protocol based on password on resisting the guessing attack.Extending the method to the three-party case,a necessary condition is concluded to guarantee the security of the three-party authenticated key exchange protocol based on the pure password.
Key concepts: Authenticated Key Exchange, Password, Zero-knowledge password proof, Computer science, Computer security, Forward secrecy, Password strength, S/KEY