Comments on “Provably Secure Dynamic Id-Based Anonymous Two-Factor Authenticated Key Exchange Protocol With Extended Security Model”

Xiaowei Li, Dengqi Yang, Xing Zeng, Benhui Chen, Yuqing Zhang · IEEE Transactions on Information Forensics and Security · 2018

Password-based authenticated key exchange (PAKE) protocol has been widely used in practice, since it is convenient for users. However, the easy-to-remember property of the password also brings security problem. In this paper, we show there is an off-line dictionary attack in an efficient PAKE protocol when the smart card is lost. In order to resist the attack, we give a countermeasure to improve it. The countermeasure makes a simple change to the original protocol which does not affect the efficiency of the protocol.

Read the paper · More papers on PaperTik