Revision and Enhancement of Two Three Party Key Agreement Protocols Vulnerable to KCI Attacks

Maurizio Adriano Strangio · World Journal of Computer Application and Technology · 2014

In two recent papers, Zuowen Tan (Security and Communication Networks) and Chih-ho Chou et al. (Computers and Electronics) published three party key agreement protocols especially convenient for protecting communications in mobile-centric environments such as e-payments, vehicular mobile networks (VMN), RFID applications, etc. For his protocol, Tan provides a formal security proof developed in a model of distributed computing based on the seminal work of Bellare and Rogaway. In this paper, we show that both protocols are vulnerable to KCI attacks. We suggest modifications to both protocols that fix the vulnerability at the expense of a small decrease in their computational efficiency.

Read the paper · More papers on PaperTik