Cryptanalysis of a Three-party Password-based Authenticated Key Exchange Protocol
Debiao He, Yuanyuan Zhang, Jianhua Chen · 2014
Key exchange protocols allow two or more parties communicating over a public network to establish a common secret key called a session key. Due to their significance in building a secure communication channel, a number of key exchange protocols have been suggested over the years for a variety of settings. Recently, Lo et al. proposed a three-party password-based authenticated key exchange (3PAKE) protocol, where two users, each shares a human-memorable password with a server, can generate a session key for future communication with the help of the server. They claimed that their scheme could resist various attacks. However, this work shows that Lo et al.’s protocol is vulnerable to an off-line password guessing attack. The analysis show Lo et al.’s protocols is not suitable for practical applications.