Improved Cross-Realm Client-to-Client Password-Authenticated Key Exchange Protocol

Junhan Yang · Journal of China University of Mining and Technology · 2010

The client-to-client password-authenticated key exchange(C2CPAKE) protocol enables two clients from different realms to agree on a common session key.The security of C2C-PAKE protocol is analyzed.The results show that the protocol is suffered from the impersonation attacks,e.g.,impersonation initiator and impersonation respondent.Based on the password verifier,an improved C2C-PAKE protocol is proposed in this paper,which can provide mutual authentication,secure session key and forward security.The improved protocol is also secure to resist server-compromise impersonation attack,password-compromise impersonation attack,off-line dictionary attack and undetectable on-line dictionary attack.

Read the paper · More papers on PaperTik