An Off-Line Dictionary Attack on a Simple Three-Party Key Exchange Protocol

作者:Nam Junghyun*; Paik Juryon; Kang Hyun Kyu; Kim Ung Mo; Won Dongho
来源:IEEE Communications Letters, 2009, 13(3): 205-207.
DOI:10.1109/LCOMM.2009.081609

摘要

Key exchange protocols allow two or more parties communicating over a public network to establish a common secret key called a session key. Due to their significance in building a secure communication channel, a number of key exchange protocols have been suggested over the years for a variety of settings. Among these is the so-called S-3PAKE protocol proposed by Lu and Cao for password-authenticated key exchange in the three-party setting. In the current work, we are concerned with the password security of the S-3PAKE protocol. We first show that S-3PAKE is vulnerable to an off-line dictionary attack in which an attacker exhaustively enumerates all possible passwords in an off-line manner to determine the correct one. We then figure out how to eliminate the security vulnerability of S-3PAKE.

  • 出版日期2009-3