Back to Search
Start Over
A security patch for a three-party key exchange protocol.
- Source :
- Wuhan University Journal of Natural Sciences; Jun2010, Vol. 15 Issue 3, p242-246, 5p
- Publication Year :
- 2010
-
Abstract
- The CLC protocol (proposed by Tzung-Her Chen, Wei-Bin Lee and Hsing-Bai Chen, CLC, for short) is a new three-party password-authenticated key exchange (3PAKE) protocol. This CLC protocol provides a superior round efficiency (only three rounds), and its resources required for computation are relatively few. However, we find that the leakage of values A<subscript> V</subscript> and B<subscript> V</subscript> in the CLC protocol will make a man-in-the-middle attack feasible in practice, where A<subscript> V</subscript> and B<subscript> V</subscript> are the authentication information chosen by the server for the participants A and B. In this paper, we describe our attack on the CLC protocol and further present a modified 3PAKE protocol, which is essentially an improved CLC protocol. Our protocol can resist attacks available, including man-in-the-middle attack we mount on the initial CLC protocol. Meanwhile, we allow that the participants choose their own passwords by themselves, thus avoiding the danger that the server is controlled in the initialization phase. Also, the computational cost of our protocol is lower than that of the CLC protocol. [ABSTRACT FROM AUTHOR]
Details
- Language :
- English
- ISSN :
- 10071202
- Volume :
- 15
- Issue :
- 3
- Database :
- Complementary Index
- Journal :
- Wuhan University Journal of Natural Sciences
- Publication Type :
- Academic Journal
- Accession number :
- 50423409
- Full Text :
- https://doi.org/10.1007/s11859-010-0312-8