An Improved Cross-Realm Client-to-Client Password-Authenticated Key Exchange Protocol

Fucai Zhou · Journal of Northeastern University · 2009

The client-to-client password-authenticated key exchange(C2C-PAKE) protocol enables two clients from different realms to agree on a shared common session key.Describing the C2C-PAKE protocol of Byun2007,its security is analyzed and it is found that the protocol is easy to suffer the attacks due to password-compromised impersonation and undetected on-line dictionary.An improved C2C-PAKE protocol is therefore proposed to introduce the public key mechanism into system security to resist those attacks effectively,especially only six operational steps are needed in relevant communication.As shown in security analysis,the protocol proposed is available to meet the security requirements.

Read the paper · More papers on PaperTik