Cryptanalysis of a Simple Three-party Key Exchange Protocol
Last modified: 2009-07-19
Abstract
Three-party authenticated key exchange (3PAKE) protocol plays an indispensable role in history of the secure communication areas in which two clients can agree a robust session key based on a human-memorable password shared with a trusted server in advance. Current research community focuses on the issue of designing a simple 3PAKE (S-3PAKE) protocol which simultaneously possesses the system security and computation efficiency. In 2008, Chung and Ku [4] pointed out that Lu and Cao’s S-3PAKE scheme [12] cannot resist three variants of the man-in-the-middle attack. The authors proposed a remedy to eliminate all identified weaknesses. Nevertheless, based on the security analyses conducted by us, the S-3PAKE mechanism proposed by Chung and Ku is still vulnerable to the undetectable on-line dictionary attacks. In this paper, we first review Chung and Ku’s S-3PAKE protocol and analyze its robustness. For security enhancement, we develop a security enhanced S-3PAKE scheme against our proposed undetectable on-line dictionary attacks