کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
393449 665652 2013 12 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر هوش مصنوعی
پیش نمایش صفحه اول مقاله
Finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
چکیده انگلیسی

Three-party password-based authenticated key exchange (3PAKE) protocols allow two users (clients) to establish a session key with the support from an authenticated server over an insecure channel. Several 3PAKE protocols, which do not require server public keys, have been proposed recently. In this paper, we use Chang et al.’s protocol as a case study and demonstrate that all of the 3PAKE protocols without server public keys are not secure against Key Compromise Impersonation (KCI) attack. A detailed analysis of flaw in these protocols has been conducted and we hope that by identifying this design flaw, similar structural mistakes can be avoided in future designs. Furthermore, we propose an improved protocol that remedies the weakness of these protocols and prove its security in a widely accepted model.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Information Sciences - Volume 235, 20 June 2013, Pages 329–340
نویسندگان
, , , ,