Strong password-based authentication in TLS using the three-party group Diffie Hellman protocol

  • Authors:
  • Michel Abdalla;Emmanuel Bresson;Olivier Chevassut;Bodo Moller;David Pointcheval

  • Affiliations:
  • Ecole normale superieure CNRS, LIENS, Paris, France.;Department of Cryptology, CELAR Technology Center, Bruz, France.;Lawrence Berkeley National Laboratory, Berkeley, CA, USA.;Horst Gortz Institute for IT Security, Ruhr-Universitat Bochum, Bochum, Germany.;Ecole normale superieure CNRS, LIENS, Paris, France

  • Venue:
  • International Journal of Security and Networks
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

The internet has evolved into a very hostile ecosystem where 'phishing' attacks are common practice. This paper shows that the three-party group Diffie-Hellman key exchange can help protect against these attacks. We have developed password-based ciphersuites for the Transport Layer Security (TLS) protocol that are not only provably secure but also believed to be free from patent and licensing restrictions based on an analysis of relevant patents in the area.