Verifier-based password-authenticated key exchange protocol in cross-realm setting
Xiumei Liu, Fucai Zhou, Guiran Chang · 2009
Most existing password-based authenticated key exchange (PAKE) protocols in cross-realm setting are based on balance scheme, which is vulnerable to password guessing attacks and server compromise attack. In this paper, we propose a verifier-based PAKE protocol in cross-realm setting called VB-4PAKE, in which the client uses a plaintext version of the password, while the server stores a verifier of the password. We also show that the proposed protocol can resist various attacks including password guessing attacks and server compromise attack.