Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
423611 | Electronic Notes in Theoretical Computer Science | 2008 | 12 Pages |
Abstract
Client-to-client password authenticated key exchange (C2C-PAKE) protocol enables two clients who only share their passwords with their own servers to establish a shared key for their secure communications. Recently, Byun et al. and Yin-Li respectively proposed first provably secure C2C-PAKE protocols. However, both protocols are found to be vulnerable to undetectable online dictionary attacks and other attacks. In this paper, we present an efficient generic construction for cross-realm C2C-PAKE protocols and prove its security in the Random-or-Real model due to Abdalla et al., without making use of the Random Oracle model.
Related Topics
Physical Sciences and Engineering
Computer Science
Computational Theory and Mathematics