The Insecurity of Wang-Cao's Certificate-Based Authenticated Key Agreement Protocol
Meng-Hui Lim, Sang-Gon Lee, Hoon Jae Lee · 한국멀티미디어학회 학술발표논문집 · 2008
Key agreement protocol is crucial in providing data confidentiality and integrity to subsequent communications among two or more parties over a public network. In 2007, Wang-Cao have proposed an escrow-free certificate-based authenticated key agreement protocol and claimed it to be secure. However, we discover that their protocol does not satisfy an important security feature that is the known session-specific temporary information security. In this paper, we discuss this problem in depth and propose a slight modification to their original scheme in order to satisfy the missing security property.