Vulnerability of Two Password-based Key Exchange and Authentication Protocols against Off-line Password-Guessing Attacks
Kyung‐Ah Shim, Hyang-Sook Lee, Juhee Lee
Abstract
Kyung‐Ah Shim, Hyang-Sook Lee, Juhee Lee
Abstract
Since a number of password-based protocols are using human memorable passwords they are vulnerable to several kinds of password guessing attacks. In this paper, we show that two password-based key exchange and authentication protocols are insecure against off-line password-guessing attacks.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Since a number of password-based protocols are using human memorable passwords they are vulnerable to several kinds of password guessing attacks. In this paper, we show that two password-based key exchange and authentication protocols are insecure against off-line password-guessing attacks.
Key concepts: Password, S/KEY, Password strength, Zero-knowledge password proof, One-time password, Computer science, Computer security, Password cracking