A secure anonymous password-based authentication protocol with control of authentication numbers
SeongHan Shin, Kazukuni Kobara · International Symposium on Information Theory and its Applications · 2016
Anonymous password-based authentication protocols are designed to provide not only password-based authentication but also client anonymity. In [10], Qian et al., proposed a simple anonymous password-based authentication (SAPAKE) protocol. In this paper, we revisit the SAPAKE protocol [10] by first showing that an outside attacker can specify which client has actually communicated with the server in the SAPAKE protocol with probability 1. Then, we propose a secure anonymous password-based authentication (for short, SAP) protocol that provides security against modification attacks on protocol-specific values, and is more efficient than SAPAKE [10]. As an additional feature, a server in the SAP protocol can control the number of anonymous client authentication.