An Improved Variant of Wang-Cao's Certificate-Based Authenticated Key Agreement Protocol
Meng-Hui Lim, Sang Gon Lee, Hoon Jae Lee · 2008
Key agreement protocol is crucial in providing data confidentiality and integrity to subsequent communications among two or more parties over a public network. In 2007, Wang-Cao have proposed an escrow-free certificate-based authenticated key agreement protocol and claimed it to be secure. However, we discover that their protocol does not satisfy an important security feature that is the known session-specific temporary information security. In this paper, we discuss this problem in depth and propose a slight modification to their original scheme in order to satisfy the missing security property.