Cryptanalysis and improvement of a password-based key exchange protocol

Fengmei Liu, Shixin Luo, Chuan-Lun Ren · 2008

In 2002, Yeh and Sun proposed a simple authenticated key agreement protocol resistant to password guessing attacks. And they provided a formal proof of security to show its strength against both passive and active adversaries. However, the scheme presented by Yeh and Sun has secure flaws. In this paper, we provide the secure analysis of the scheme and show that it can not resist the stolen-verifier attack and manin-the-middle attack. Then we presents an improved scheme of the Yeh-Sun’s scheme which is resistant to the stolen-verifier attack combining with man-in-the-middle attack.

Read the paper · More papers on PaperTik