Skip to main navigation Skip to search Skip to main content

Improvement of a three-party password-based key exchange protocol with formal verification

  • Qi Xie
  • , Na Dong
  • , Xiao Tan
  • , Duncan S. Wong
  • , Guilin Wang

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

A Three-Party Password-based Authenticated Key Exchange (3PAKE) protocol allows two users to establish a secure session key over an insecure communication channel with the help of a third party, which is a trusted server. Recently, Lou and Huang proposed a 3PAKE which is efficient and suitable for running on resource-constrained devices such as smart cards and mobile phones. In this paper, we show that their scheme is vulnerable to off-line password guessing attack and partition attack. We then propose an efficient method to fix these problems. Additionally, the mutual authentication and session key secrecy of the proposed protocol are verified using a formal verification tool.
Original languageEnglish
Pages (from-to)231-237
JournalInformation Technology and Control
Volume42
Issue number3
DOIs
Publication statusPublished - Sept 2013

Research Keywords

  • Key exchange
  • Password based authenticated key exchange (PAKE)
  • ProVerif
  • Three-party PAKE

Fingerprint

Dive into the research topics of 'Improvement of a three-party password-based key exchange protocol with formal verification'. Together they form a unique fingerprint.

Cite this