2006Journal of the Graduate School of the Chinese Academy of SciencesRequires access

Cryptanalysis and Improvement of Client-to-Client Password Authenticated Key Exchange Protocol

Bao Li

Open publisher page 0 citations

Abstract

Most password-based key exchange protocols consider how to exchange a session key between a client and a server.Client-to-Client password authenticated key exchange protocol considers the scenario where two clients want to establish a session key,but they only share their passwords with their own servers. In Ref.[1],Jin Wook Byun et al proposed two such protocols called cross-realm C2C-PAKE and single-server C2C-PAKE.Recently,some flaws of these two protocols are found and some improvements are suggested.In this paper,we show that the cross-realm C2C-PAKE protocol and its all improved forms are still insecure.And we also present a new cross-realm C2C-PAKE protocol which is resistant to all known attacks.

About this research paper

What this paper is about

Most password-based key exchange protocols consider how to exchange a session key between a client and a server.Client-to-Client password authenticated key exchange protocol considers the scenario where two clients want to establish a session key,but they only share their passwords with their own servers. In Ref.[1],Jin Wook Byun et al proposed two such protocols called cross-realm C2C-PAKE and single-server C2C-PAKE.Recently,some flaws of these two protocols are found and some improvements are suggested.In this paper,we show that the cross-realm C2C-PAKE protocol and its all improved forms are still insecure.And we also present a new cross-realm C2C-PAKE protocol which is resistant to all known attacks.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Most password-based key exchange protocols consider how to exchange a session key between a client and a server.Client-to-Client password authenticated key exchange protocol considers the scenario where two clients want to establish a session key,but they only share their passwords with their own servers. In Ref.[1],Jin Wook Byun et al proposed two such protocols called cross-realm C2C-PAKE and single-server C2C-PAKE.Recently,some flaws of these two protocols are found and some improvements are suggested.In this paper,we show that the cross-realm C2C-PAKE protocol and its all improved forms are still insecure.And we also present a new cross-realm C2C-PAKE protocol which is resistant to all known attacks.

Key concepts: Authenticated Key Exchange, Computer science, Key exchange, Password, Computer security, Oakley protocol, Session (web analytics), Key (lock)

Related papers

Back to paper searchBrowse research topicsOriginal source
Cryptanalysis and Improvement of Client-to-Client Password Authenticated Key Exchange Protocol — Research Paper | ScholarLens