Efficient Three-Party Authentication and Key Agreement Protocols Resistant to Password Guessing Attacks

Her‐Tyan Yeh, Hung Sun, Tzonelih Hwang · 2003

Three-party EKE was proposed to establish a session key between two clients through a server. However, three-party EKE is insecure against undetectable on-line and off-line password guessing attacks. In this paper, we first propose an enhanced three-party EKE to withstand the security risk in three-party EKE. We also propose a verifier-based three-party EKE that is more secure than a plaintext-equivalent mechanism in which a compromise of the server’s database will not result in success in directly impersonating clients.

Read the paper · More papers on PaperTik