An Improvement of Certification-based One-Round Tripartite Key Agreement Protocols

Kambombo Mtong, Eun‐Jun Yoon · IEIE Transactions on Smart Processing and Computing · 2013

Key agreement protocols allow multi-parties exchanging public information to create a common secret key that is known only to those entities over an insecure network. Since Joux first published the pairing-based one round tripartite key agreement protocol, many authenticated protocols have been proposed. Unfortunately, many of them have been broken while others have been shown to be deficient in some desirable security attributes. In 2004, Cheng et al. presented two protocols aimed at strengthening Shim’s certificate-based and Zhang et al.’s tripartite identitybased protocols. This paper reports that 1) In Cheng et al.’s identity-based protocol, an adversary can extract long-term private keys of all the parties involved; and 2) Cheng et al.’s certificationbased protocol is weak against key integrity attacks. This paper suggests possible remedies for the security flaws in both protocols and then presents a modified Cheng et al.’s identity-based, oneround tripartite protocol that is more secure than the original protocol.

Read the paper · More papers on PaperTik