Cryptanalysis of a client-to-client password-authenticated key agreement protocol.
Fengjiao Wang, Yuqing Zhang · 2008
Abstract—Recently, Byun et al. proposed an efficient client-to-client password-authenticated key agreement protocol (EC2C-PAKA), which was provably secure in a formally defined security model. This letter shows that man-in-the-middle attack to the communication between clients. This letter reviews the EC2C-PAKA protocol proposed by Byun et al. [5] and shows that it suffers from password EC2C-PAKA protocol is vulnerable to password compromise impersonate attack and key compromise compromise impersonate attack and man-in-the-middle attack if the key between servers is compromised. man-in-the-middle attack. We note that the password compromise impersonate attack cannot be prohibited only Index Terms — Cryptanalysis, EC2C-PAKA, by sharing a password between client and server, nor does impersonate attack, man-in-the-middle attack. the key compromise man-in-the-middle attack by adopting symmetric encryption between servers. U I.