An enhanced password authenticated key exchange protocol without server public keys

Maryam Saeed, Ali Mackvandi, Mansour Naddafiun, Hamid reza Karimnejad · 2012

Password Authenticated Key Exchange (PAKE) protocols permit two entities to generate a large common session key and authenticate each other based on a pre-shared human memorable password. In 2006, Strangio proposed the DH-BPAKE protocol and claimed that the mentioned protocol is provably secure against several attacks. In this paper, it is shown that the DH-BPAKE protocol is vulnerable to password compromise impersonation attack and it is not efficient due to the number of running steps and its computational load. To overcome these weaknesses, an enhanced PAKE protocol is proposed which provides several security properties. In addition, it is proved that our proposed scheme is more sefficient1(Secure & Efficient) in comparison with DH-BPAKE protocol.

Read the paper · More papers on PaperTik