Security Issues of a Three-Party Password Authenticated Key Exchange Protocol Resistant to Stolen Smart Card Attacks

Soumyajit Nag, Subhasish Banerjee · 2018

In todays date, privacy and authentication blend together in different aspects of life. The Authenticate Key Agreement Protocol is a very crucial and an essential cryptographic parameter, which enables to establish a bridge in a secure transaction onto a public channel. A Three Party Authenticate Key Agreement Protocol is yet another essential ingredient which helps to land such a secured procedure of transaction. In this case a secured server makes the verification of authenticity of the user, whether he is genuine or not. There are an ample number of scholars those are working on Three Party Authenticate Key Agreement Protocols till date. Recently it has been found that Chen et. al. has concurred a Three Party Password based Authenticate Key Exchange Protocol which is allegedly known to be a firewall against the stolen smart card attack and user impersonation attack. This simplifies that, even though a smart card belonging to an authenticate user gets lost, the adversary remains harmless to bring any kind of catastrophic movement to that card or even to the possessor. Despite of all the effort of providing a safe background to the card, it remains the same and unforeseeable to pinpoint the user anonymity. After analysing through the whole research, it has been accumulated that the immense drawback of Chen et. al.'s protocol lies on the foundation of on-line password guessing attack. In the concerned paper we are a leap forward to describe how Chen et. al.'s protocol is prone to the on-Line Password Guessing Attack.

Read the paper · More papers on PaperTik