ISCAS OpenIR
finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys
Xiong Hu; Chen Yanan; Guan Zhi; Chen Zhong
2013
发表期刊Information Sciences
ISSN0020-0255
页码-
摘要Three-party password-based authenticated key exchange (3PAKE) protocols allow two users (clients) to establish a session key with the support from an authenticated server over an insecure channel. Several 3PAKE protocols, which do not require server public keys, have been proposed recently. In this paper, we use Chang et al.'s protocol as a case study and demonstrate that all of the 3PAKE protocols without server public keys are not secure against Key Compromise Impersonation (KCI) attack. A detailed analysis of flaw in these protocols has been conducted and we hope that by identifying this design flaw, similar structural mistakes can be avoided in future designs. Furthermore, we propose an improved protocol that remedies the weakness of these protocols and prove its security in a widely accepted model. © 2013 Elsevier Inc. All rights reserved.; Three-party password-based authenticated key exchange (3PAKE) protocols allow two users (clients) to establish a session key with the support from an authenticated server over an insecure channel. Several 3PAKE protocols, which do not require server public keys, have been proposed recently. In this paper, we use Chang et al.'s protocol as a case study and demonstrate that all of the 3PAKE protocols without server public keys are not secure against Key Compromise Impersonation (KCI) attack. A detailed analysis of flaw in these protocols has been conducted and we hope that by identifying this design flaw, similar structural mistakes can be avoided in future designs. Furthermore, we propose an improved protocol that remedies the weakness of these protocols and prove its security in a widely accepted model. © 2013 Elsevier Inc. All rights reserved.
收录类别EI
关键词Artificial Intelligence Software Engineering
部门归属(1) School of Computer Science and Engineering The University of Electronic Science and Technology of China Chengdu PR China; (2) State Key Laboratory of Rail Traffic Control and Safety Beijing Jiao Tong University Beijing PR China; (3) Institute of Software School of Electronics Engineering and Computer Science Peking University Beijing PR China; (4) State Key Laboratory of Information Security Institute of Software Chinese Academy of Sciences Beijing PR China
语种英语
WOS记录号WOS:000317887100023
引用统计
被引频次:19[WOS]   [WOS记录]     [WOS相关记录]
内容类型期刊论文
URI标识http://ir.iscas.ac.cn/handle/311060/15214
专题中国科学院软件研究所
推荐引用方式
GB/T 7714
Xiong Hu,Chen Yanan,Guan Zhi,et al. finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys[J]. Information Sciences,2013:-.
APA Xiong Hu,Chen Yanan,Guan Zhi,&Chen Zhong.(2013).finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys.Information Sciences,-.
MLA Xiong Hu,et al."finding and fixing vulnerabilities in several three-party password authenticated key exchange protocols without server public keys".Information Sciences (2013):-.
条目包含的文件
条目无相关文件。
个性服务
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
谷歌学术
谷歌学术中相似的文章
[Xiong Hu]的文章
[Chen Yanan]的文章
[Guan Zhi]的文章
百度学术
百度学术中相似的文章
[Xiong Hu]的文章
[Chen Yanan]的文章
[Guan Zhi]的文章
必应学术
必应学术中相似的文章
[Xiong Hu]的文章
[Chen Yanan]的文章
[Guan Zhi]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
暂无评论
 

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。