Welcome to Journal of University of Chinese Academy of Sciences,Today is

Journal of University of Chinese Academy of Sciences ›› 2006, Vol. 23 ›› Issue (6): 793-801.DOI: 10.7523/j.issn.2095-6134.2006.6.012

Previous Articles     Next Articles

Cryptanalysis and Improvement of Client-to-Client Password Authenticated Key Exchange Protocol

YIN Yin, LI Bao   

  1. State Key Laboratory of Information Security(Graduate School of Chinese Academy of Sciences), Beijing 100049, China
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-11-15

Abstract: Most password-based key exchange protocols consider how to exchange a session key between a client and a server. Client-to-Client password authenticated key exchange protocol considers the scenario where two clients want to establish a session key but they only share their passwords with their own servers. In [1], Jin Wook Byun et al. proposed two such protocols called cross-realm C2C-PAKE and single-server C2C-PAKE. Recently some flaws of these two protocols are found and some improvements are suggested. In this paper, we show that the cross-realm C2C-PAKE protocol and its all improved forms are still insecure. And we also present a new cross-realm C2C-PAKE protocol which is resistant to all known attacks.

CLC Number: