Security Enhancement of Ku-Wang Authenticated Key Agreement Protocol
Chin‐Chen Chang, Jung-San Lee · 2008
Authenticated key agreement protocol is an essential cryptographic tool for permitting two participants, Alice and Bob, who never met before to authenticate each other and negotiate a common session key in an insecure network. In 1999, Seo and Sweeney first proposed an authenticated key agreement protocol using a pre-shared password. Later, Tseng pointed out that Seo and Sweeney's protocol suffered from the replay attack. Tseng then presented an improvement to repair the weakness. Unfortunately, Ku and Wang soon showed that Tseng's protocol is insecure against the modification attack and the replay attack. Then, Ku and Wang proposed an improved version to overcome the weakness from which Tseng's protocol suffered. However, we find that Ku and Wang's protocol is vulnerable to the off-line password guessing attack. In this article, we will show the security flaw of Ku and Wang's protocol and present an improved authenticated key agreement protocol.