A provably secure and efficient two-party password-based explicit authenticated key exchange protocol resistance to password guessing attacks

被引:8
|
作者
Farash, Mohammad Sabzinejad [1 ]
Islam, S. K. Hafizul [2 ]
Obaidat, Mohammad S. [3 ]
机构
[1] Kharazmi Univ, Fac Math Sci & Comp, Tehran, Iran
[2] Birla Inst Technol & Sci, Dept Comp Sci & Informat Syst, Pilani 333031, Rajasthan, India
[3] Monmouth Univ, Dept Comp Sci, West Long Branch, NJ 07764 USA
来源
关键词
authenticated key exchange; password-based protocol; elliptic curve; bilinear pairing; off-line password guessing attack; random oracle model; AGREEMENT PROTOCOL; MUTUAL AUTHENTICATION; CRYPTANALYSIS; IMPROVEMENT; SCHEME;
D O I
10.1002/cpe.3477
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password-based two-party authenticated key exchange (2PAKE) protocol enables two or more entities, who only share a low-entropy password between them, to authenticate each other and establish a high-entropy secret session key. Recently, Zheng et al. proposed a password-based 2PAKE protocol based on bilinear pairings and claimed that their protocol is secure against the known security attacks. However, in this paper, we indicate that the protocol of Zheng et al. is insecure against the off-line password guessing attack, which is a serious threat to such protocols. Consequently, we show that an attacker who obtained the users' password by applying the off-line password guessing attack can easily obtain the secret session key. In addition, the protocol of Zheng et al. does not provide the forward secrecy of the session key. As a remedy, we also improve the protocol of Zheng et al. and prove the security of our enhanced protocol in the random oracle model. The simulation result shows that the execution time of our 2PAKE protocol is less compared with other existing protocols. Copyright (c) 2015 John Wiley & Sons, Ltd.
引用
收藏
页码:4897 / 4913
页数:17
相关论文
共 50 条
  • [1] Provably Secure Gateway-Oriented Password-Based Authenticated Key Exchange Protocol Resistant to Password Guessing Attacks
    Chien, Hung-Yu
    Wu, Tzong-Chen
    Yeh, Ming-Kuei
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2013, 29 (02) : 249 - 265
  • [2] Provably secure three-party password-based authenticated key exchange protocol
    Zhao, Jianjie
    Gu, Dawu
    [J]. INFORMATION SCIENCES, 2012, 184 (01) : 310 - 323
  • [3] Efficient provably secure password-based explicit authenticated key agreement
    Ruan, Ou
    Kumar, Neeraj
    He, Debiao
    Lee, Jong-Hyouk
    [J]. PERVASIVE AND MOBILE COMPUTING, 2015, 24 : 50 - 60
  • [4] Efficient and secure password-based authenticated key exchange protocol
    Wu, Shuhua
    Zhu, Yuefei
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 1269 - 1272
  • [5] A Secure Two-Party Password-Authenticated Key Exchange Protocol
    Saeed, Maryam
    Shahhoseini, Hadi Shahriar
    Mackvandi, Ali
    Rezaeinezhad, Mohammad Reza
    Naddafiun, Mansour
    Bidoki, Mohammad Zare
    [J]. 2014 IEEE 15TH INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION (IRI), 2014, : 466 - 474
  • [6] A secure and efficient three-party password-based authenticated key exchange protocol
    He, Yong-Zhong
    Cai, Ying
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL SYMPOSIUM ON DATA, PRIVACY, AND E-COMMERCE, 2007, : 280 - +
  • [7] An Efficient Provably Secure Password-Based Authenticated Key Agreement
    Xu, Hanqiu
    Wang, Qingping
    Zhou, Jing
    Ruan, Ou
    [J]. INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2017, 2018, 612 : 423 - 434
  • [8] An efficient and provably secure three-party password-based authenticated key exchange protocol based on Chebyshev chaotic maps
    Farash, Mohammad Sabzinejad
    Attari, Mahmoud Ahmadian
    [J]. NONLINEAR DYNAMICS, 2014, 77 (1-2) : 399 - 411
  • [9] An efficient and provably secure three-party password-based authenticated key exchange protocol based on Chebyshev chaotic maps
    Mohammad Sabzinejad Farash
    Mahmoud Ahmadian Attari
    [J]. Nonlinear Dynamics, 2014, 77 : 399 - 411
  • [10] Provably secure three-party password-based authenticated key exchange protocol using Weil pairing
    Wen, HA
    Lee, TF
    Hwang, T
    [J]. IEE PROCEEDINGS-COMMUNICATIONS, 2005, 152 (02): : 138 - 143