Ultimate solution to authentication via memorable password
Taerim Kwon · 2000
A new password authentication and key agreement protocol called AMP is proposed in a provable manner. Human-memorable password authentication is not easy to provide over insecure networks due to the low entropy of the password. A cryptographic protocol, based on the public-key cryptography, is the most promising solution to this problem. AMP provides the password-verifier based authentication and the Diffie-Hellman key agreement, securely and efficiently. AMP is easy to generalize in any other cyclic groups. Verifier-based protocols allow the asymmetric model in which a client possesses a password, while a server stores its verifier. AMP is actually the most efficient protocol among those protocols. Several variants of AMP are also proposed. They are called AMP i , AMP n , AMP + , AMP ++ . Among them, AMP n is a pure password-based protocol rather than a verifier-based protocol. In the end, we give a rigorous comparison to the related protocols.