Article ID Journal Published Year Pages File Type
454279 Computer Standards & Interfaces 2008 6 Pages PDF
Abstract

In 2004, Chang and Chang proposed a three-party encrypted key exchange (ECC-3PEKE) protocol without using the server's public keys. They claimed that their proposed ECC-3PEKE protocol is secure, efficient, and practical. Unlike their claims, the ECC-3PEKE protocol, however, is still susceptible to undetectable on-line password guessing attacks. Accordingly, the current paper demonstrates the vulnerability of Chang–Chang's ECC-3PEKE protocol regarding undetectable on-line password guessing attacks and than presents an enhancement to resolve such security problems.

Related Topics
Physical Sciences and Engineering Computer Science Computer Networks and Communications
Authors
, ,