• DocumentCode
    2989407
  • Title

    Cryptoanalysis and Improvement of Verifier-based Key Agreement Protocol in Cross-Realm Setting

  • Author

    Li, Jing-feng ; Guo, Wei-feng ; Zhang, Lai-shun ; Li, Yun-peng

  • Author_Institution
    Zhengzhou Inf. Sci. & Technol. Inst., Zhengzhou, China
  • fYear
    2011
  • fDate
    3-4 Dec. 2011
  • Firstpage
    925
  • Lastpage
    929
  • Abstract
    Most password-authenticated key agreement protocols have focused on authenticated key agreement using shared password between a client and a server. With the emergence of a variety of communication environments such as EPC global network, it is necessary to construct a secure channel between clients. Cross-realm client-to-client password-authenticated key agreement (C2C-PAKA) protocol can provide secure authenticated key agreement for two clients of different realms, who only share their passwords with their own servers. In 2009, Liu proposed a verifier-based key exchange protocol in cross-realm setting. However, the protocol is susceptible to server compromise attack. In this paper, we propose an improved verifier-based cross-realm C2C-PAKA protocol based on EC2C-PAKA protocol. While holding all the claiming security characteristics of the original protocol, the new protocol can resist server compromise attack. We have proved the improved protocol is secure under the Diffie-Hellman assumption and discrete logarithm assumption. In addition, the improved protocol only requires 12 modular exponentiation, which is more efficient and thus of greater practicality than previous solutions.
  • Keywords
    client-server systems; computer network security; cryptographic protocols; C2C-PAKA protocol; Diffie-Hellman assumption; EC2C-PAKA protocol; EPCglobal network; cross realm setting; cryptoanalysis; discrete logarithm assumption; password authenticated key agreement protocols; server compromise attack; shared password; verifier based key agreement protocol; Authentication; Dictionaries; Encryption; Erbium; Protocols; Servers; C2C-PAKA; EPCglobal; authentication; cross-realm;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Security (CIS), 2011 Seventh International Conference on
  • Conference_Location
    Hainan
  • Print_ISBN
    978-1-4577-2008-6
  • Type

    conf

  • DOI
    10.1109/CIS.2011.208
  • Filename
    6128259