An improved provably secure three-party key exchange protocol
Maw-Jinn Tsaur, Jenn-Wei Lin, Wei‐Chi Ku, Yu-Ze Shen · 2010
Recently, Chung and Ku showed that the S-3PAKE (simple three-party password-based authenticated key exchange) protocol proposed by Lu and Cao is vulnerable to an impersonation-of-initiator attack, an impersonation-of-responder attack, and a man-in-the-middle attack, and then proposed an enhanced version. Unfortunately, Phan et al. showed that Chung-Ku's protocol still cannot resist two password guessing attacks. In this paper, we propose an improved protocol that can resist password guessing attacks. Furthermore, we offer a formally provable security theorem to evaluate the AKE security of the improved protocol.