• DocumentCode
    3781530
  • Title

    Gateway threshold password-based Authenticated Key Exchange secure against Undetectable On-line Dictionary Attack

  • Author

    Yukou Kobayashi;Naoto Yanai;Kazuki Yoneyama;Takashi Nishide;Goichiro Hanaoka;Kwangjo Kim;Eiji Okamoto

  • Author_Institution
    University of Tsukuba, Ibaraki, Japan
  • Volume
    4
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    39
  • Lastpage
    52
  • Abstract
    Password-based Authenticated Key Exchange (PAKE) allows a server to authenticate a user and to establish a session key shared between the server and the user just by having memorable passwords. In PAKE, conventionally the server is assumed to have the authentication functionality and also provide on-line services simultaneously. However, in the real-life applications, this may not be the case, and the authentication server may be separate from on-line service providers. In such a case, there is a problem that a malicious service provider with no authentication functionality may be able to guess the passwords by interacting with other participants repeatedly. Abdalla et al. put forward a notion of the server password protection security to deal with this problem. However, their proposed schemes turned out to be vulnerable to Undetectable On-line Dictionary Attack (UDonDA). To cope with this situation, we propose the Gateway Threshold PAKE provably secure against this password guessing attack by also taking the corruption of authentication servers into consideration.
  • Keywords
    "Servers","Authentication","Logic gates","Protocols","Dictionaries","Resistance"
  • Publisher
    ieee
  • Conference_Titel
    e-Business and Telecommunications (ICETE), 2015 12th International Joint Conference on
  • Type

    conf

  • Filename
    7518020