Back to Search Start Over

A security patch for a three-party key exchange protocol.

Authors :
Zhao, Jianjie
Gu, Dawu
Source :
Wuhan University Journal of Natural Sciences; Jun2010, Vol. 15 Issue 3, p242-246, 5p
Publication Year :
2010

Abstract

The CLC protocol (proposed by Tzung-Her Chen, Wei-Bin Lee and Hsing-Bai Chen, CLC, for short) is a new three-party password-authenticated key exchange (3PAKE) protocol. This CLC protocol provides a superior round efficiency (only three rounds), and its resources required for computation are relatively few. However, we find that the leakage of values A<subscript> V</subscript> and B<subscript> V</subscript> in the CLC protocol will make a man-in-the-middle attack feasible in practice, where A<subscript> V</subscript> and B<subscript> V</subscript> are the authentication information chosen by the server for the participants A and B. In this paper, we describe our attack on the CLC protocol and further present a modified 3PAKE protocol, which is essentially an improved CLC protocol. Our protocol can resist attacks available, including man-in-the-middle attack we mount on the initial CLC protocol. Meanwhile, we allow that the participants choose their own passwords by themselves, thus avoiding the danger that the server is controlled in the initialization phase. Also, the computational cost of our protocol is lower than that of the CLC protocol. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
10071202
Volume :
15
Issue :
3
Database :
Complementary Index
Journal :
Wuhan University Journal of Natural Sciences
Publication Type :
Academic Journal
Accession number :
50423409
Full Text :
https://doi.org/10.1007/s11859-010-0312-8