A New C2C-PAKE Protocol in Cross-Realm Setting
Xiumei Liu, Fucai Zhou, Guiran Chang · 2008
Most existing cross-realm client-to-client (C2C) key exchange protocols are based on password authentication, which are vulnerable to password guessing attacks. Sun et al. and Lee et al. have proposed three-party key exchange protocols respectively, which achieve higher security through verifier authentication instead of password authentication. However, their key exchange protocols can only be used in single-server C2C setting. In this paper, we propose a new cross-realm C2C-PAKE protocol, which is based on verifier authentication, and enable two clients to agree on a common session key with assistance of two servers in different realms. The protocol is shown to be resistant against various attacks including password guessing attacks and server compromise attack.