A New C2C-PAKE Protocol in Cross-Realm Setting

Xiumei Liu, Fucai Zhou, Guiran Chang · 2008

Most existing cross-realm client-to-client (C2C) key exchange protocols are based on password authentication, which are vulnerable to password guessing attacks. Sun et al. and Lee et al. have proposed three-party key exchange protocols respectively, which achieve higher security through verifier authentication instead of password authentication. However, their key exchange protocols can only be used in single-server C2C setting. In this paper, we propose a new cross-realm C2C-PAKE protocol, which is based on verifier authentication, and enable two clients to agree on a common session key with assistance of two servers in different realms. The protocol is shown to be resistant against various attacks including password guessing attacks and server compromise attack.

Read the paper · More papers on PaperTik