Password-authenticated 3PEKE with round efficiency without server's public key
Ya‐Fen Chang, Chin‐Chen Chang · 2005
People only can remember simple or meaningful passwords. In three-party key exchange protocols with password authentication, a client is allowed to share an easy-to-remember password with a trusted server so that two users can negotiate a session key for secure communication. Steiner et al. proposed a three-party protocol based on the encrypted key exchange protocols in 1995; but, their protocol suffered from off-line and undetectable on-line password guessing attacks. In 2000, Lin et al. proposed a secure three-party protocol with server's public key. Since a certificate is needed, this protocol is not practical for some environments. In 2001, Lin et al. proposed a new three-party protocol without server's public key with two more rounds. Later, Lin et al. proposed an improvement. We propose a secure three-party EKE protocol with only five rounds in this paper.