Password-based client authentication for SSL/TLS using ElGamal and Chebyshev polynomials
Kazim Sarikaya, Ahmet Burak Can · 2011
A system that does remote user authentication needs a secure channel for confidentiality of user authentication information. The SSL/TLS protocol can provide such a secure channel. This protocol can use client certificates to authenticate clients. The digital certificate is an inconvenient and expensive way for client authentication. Hence password-based authentication is used by most systems. The TLS-SRP, an extension of TLS protocol, can do password-based client authentication inside handshaking part of TLS. The TLS-SRP is based on Diffie-Hellman key exchange protocol. In this paper, three approaches for password-based client authentication are defined using Chebyshev polynomials and ElGamal algorithm. These approaches are implemented as a TLS extension and compared with TLS-SRP extension.