Stronger password-base authenticated key exchange protocols
Maobian Chen, Xiufeng Wang · 2008
Password authenticated key exchange protocols (PAKE) are designed to be secure over insecure networks even the users pick up a human-memorable password from a small space. Although a great deal of research of PAKE has been proposed and many formal definitions and settings in the area of AKE have been defined, few formal definitions and settings on PAKE are proposed. We, in this paper, extend and modify existing models and settings of AKE to the ones of PAKE so that our definitions can capture more realistic attacks on PAKE protocols than previous definitions and offer more powers to an adversary to break the protocols. In addition, we show that the protocols proposed by Halevi and Krawczyk are insecure in our definitions. After analyzing the attacks against their protocols, we extend and modify their protocols so that the extended protocols are secure in our definitions. Besides, our protocols can resist password exposure even if the long-term key is compromised.