Weaknesses of a Verifier-Based Password-Authenticated Key Exchange Protocol in the Three-Party Setting
Qiong Pu, Wei Liu
Abstract
Qiong Pu, Wei Liu
Abstract
Quite recently, Li et al's suggested an efficient verifier-based password-authentication key exchange protocol via elliptic curves. In this paper, we shows that their protocol is still vulnerable to off-line dictionary attack and unknown key-share attack. Through our work, we hope the similar mistakes can be avoided in future designs.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Quite recently, Li et al's suggested an efficient verifier-based password-authentication key exchange protocol via elliptic curves. In this paper, we shows that their protocol is still vulnerable to off-line dictionary attack and unknown key-share attack. Through our work, we hope the similar mistakes can be avoided in future designs.
Key concepts: Computer science, Password, Authenticated Key Exchange, Dictionary attack, Zero-knowledge password proof, Computer security, Key exchange, Key (lock)