Security Weaknesses in Chang and Wu's Key Agreement Protocol for a Multi-Server Environment

Youngsook Lee, Dongho Won · 2008

Recently, Chang and Wu have proposed an efficient key agrement protocol suited for a multi-server environment. This work reviews Chang and Wu's protocol and provides a security analysis on the protocol. Our analysis shows that Chang and Wu's protocol does not achieve its fundamental goal not only of password security but also of mutual authentication. We demonstrate these security flaws by mounting an off-line password guessing attack and two impersonation attacks, the sever impersonation attack and the user impersonation attack on Chang and Wu's protocol. In addition, we found that the protocol is vulnerable to an attack against perfect forward secrecy.

Read the paper · More papers on PaperTik