DocumentCode
623690
Title
Cross-domain password-based authenticated key exchange revisited
Author
Liqun Chen ; Hoon Wei Lim ; Guomin Yang
Author_Institution
HP Labs., Bristol, UK
fYear
2013
fDate
14-19 April 2013
Firstpage
1052
Lastpage
1060
Abstract
We revisit the problem of cross-domain secure communication between two users belonging to different security domains within an open and distributed environment. Existing approaches presuppose that either the users are in possession of public key certificates issued by a trusted certificate authority (CA), or the associated domain authentication servers share a long-term secret key. In this paper, we propose a four-party password-based authenticated key exchange (4PAKE) protocol that takes a different approach from previous work. The users are not required to have public key certificates, but they simply reuse their login passwords they share with their respective domain authentication servers. On the other hand, the authentication servers, assumed to be part of a standard PKI, act as ephemeral CAs that “certify” some key materials that the users can subsequently exchange and agree on a session key. Moreover, we adopt a compositional approach. That is, by treating any secure two-party password-based key exchange protocol and two-party asymmetric-key based key exchange protocol as black boxes, we combine them to obtain a generic and provably secure 4PAKE protocol.
Keywords
cryptographic protocols; public key cryptography; telecommunication security; cross-domain password-based authenticated key exchange; cross-domain secure communication; domain authentication servers; four-party password-based authenticated key exchange protocol; long-term secret key; public key certificates; trusted certificate; two-party asymmetric-key based key exchange protocol; two-party password-based key exchange protocol; Authentication; Electronic mail; Materials; Protocols; Public key; Servers; Password-based protocol; client-to-client; cross-domain; key exchange;
fLanguage
English
Publisher
ieee
Conference_Titel
INFOCOM, 2013 Proceedings IEEE
Conference_Location
Turin
ISSN
0743-166X
Print_ISBN
978-1-4673-5944-3
Type
conf
DOI
10.1109/INFCOM.2013.6566895
Filename
6566895
Link To Document