Back to Search
Start Over
A novel three-party password-based authenticated key exchange protocol with user anonymity based on chaotic maps
- Source :
- Soft Computing. 22:2495-2506
- Publication Year :
- 2017
- Publisher :
- Springer Science and Business Media LLC, 2017.
-
Abstract
- Three-party authenticated key exchange (3PAKE) protocol allows two communication users to authenticate each other and to establish a secure common session key with the help of a trusted remote server. Recently, Farash and Attari propose an efficient and secure 3PAKE protocol based on Chebyshev chaotic maps and their protocol is supported by the formal proof in the random oracle model. However, in this paper, we analyze the security of Farash–Attari’s protocol and show that it fails to resist password disclosure attack if the secret information stored in the server side is compromised. In addition, their protocol is insecure against user impersonation attack and the server is not aware of having caused problem. Moreover, the password change phase is insecure to identify the validity of request where insecurity in password change phase can cause offline password guessing attacks and is not easily reparable. To remove these security weaknesses, based on Chebyshev chaotic maps and quadratic residues, we further design an improved protocol for 3PAKE with user anonymity. In comparison with the existing chaotic map-based 3PAKE protocols, our proposed 3PAKE protocol is more secure with acceptable computation complexity and communication overhead.
- Subjects :
- Zero-knowledge password proof
Computer science
02 engineering and technology
Oakley protocol
Computer security
computer.software_genre
01 natural sciences
One-time password
Theoretical Computer Science
Password strength
S/KEY
Random oracle
0103 physical sciences
Universal composability
0202 electrical engineering, electronic engineering, information engineering
Session key
010301 acoustics
Password
Password policy
Authentication
Password cracking
Authenticated Key Exchange
020201 artificial intelligence & image processing
Geometry and Topology
computer
Software
Subjects
Details
- ISSN :
- 14337479 and 14327643
- Volume :
- 22
- Database :
- OpenAIRE
- Journal :
- Soft Computing
- Accession number :
- edsair.doi...........207437d76ea13da9f4b4625facb87b29
- Full Text :
- https://doi.org/10.1007/s00500-017-2504-z