Cryptanalysis of a robust key agreement based on public key authentication

Mohsen Toorani · Security and Communication Networks · 2015

Abstract This paper considers security analysis of the YAK, a public key‐based authenticated key agreement protocol. The YAK protocol is a variant of the two‐pass HMQV protocol but uses zero‐knowledge proofs for proving knowledge of ephemeral values. In this paper, we show that the YAK protocol lacks joint key control and perfect forward secrecy attributes and is vulnerable to some attacks including unknown key‐share and key‐replication attacks. This invalidates the semantic security of the protocol in several security models. There are also other considerations regarding the impersonation and small subgroup attacks. Copyright © 2015 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik