Cryptanalysis and Improvement of EC2C-PAKA Protocol in Cross-Realm
Fucai Zhou, Xiumei Liu, Hong Yan, Guiran Chang · 2008
Byun et al. proposed a cross-realm client-to-client password-authenticated key exchange (C2C-PAKE) protocol in ICICS'02. The protocol enables two clients in different realms to agree on a common session key by using different passwords. In this paper, we analyze Byun et al.'s new efficient client-to-client password-authenticated key agreement (EC2C-PAKA) protocol of 2007, and show that the efficient protocol is vulnerable to password-compromise impersonation attack. In addition, we present an improved client-to-client password-authenticated key agreement protocol in cross-realm based on public-key. By analyzing the security attributes and performances, we show that our improved protocol can resist many attacks and is more efficient.