Welcome to Journal of University of Chinese Academy of Sciences,Today is

Cryptanalysis and Improvement of Client-to-Client Password Authenticated Key Exchange Protocol

  • YIN Yin ,
  • LI Bao
Expand
  • State Key Laboratory of Information Security(Graduate School of Chinese Academy of Sciences), Beijing 100049, China

Received date: 1900-01-01

  Revised date: 1900-01-01

  Online published: 2006-11-15

Abstract

Most password-based key exchange protocols consider how to exchange a session key between a client and a server. Client-to-Client password authenticated key exchange protocol considers the scenario where two clients want to establish a session key but they only share their passwords with their own servers. In [1], Jin Wook Byun et al. proposed two such protocols called cross-realm C2C-PAKE and single-server C2C-PAKE. Recently some flaws of these two protocols are found and some improvements are suggested. In this paper, we show that the cross-realm C2C-PAKE protocol and its all improved forms are still insecure. And we also present a new cross-realm C2C-PAKE protocol which is resistant to all known attacks.

Cite this article

YIN Yin , LI Bao . Cryptanalysis and Improvement of Client-to-Client Password Authenticated Key Exchange Protocol[J]. Journal of University of Chinese Academy of Sciences, 2006 , 23(6) : 793 -801 . DOI: 10.7523/j.issn.2095-6134.2006.6.012

Outlines

/