A secure password-authenticated key exchange between clients with different passwords

  • Authors:
  • Eun-Jun Yoon;Kee-Young Yoo

  • Affiliations:
  • Department of Computer Engineering, Kyungpook National University, Daegu, Republic of Korea;Department of Computer Engineering, Kyungpook National University, Daegu, Republic of Korea

  • Venue:
  • APWeb'06 Proceedings of the 2006 international conference on Advanced Web and Network Technologies, and Applications
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In 2004, Kim et al. proposed an improvement to Byun et al.’s client to client password-authenticated key exchange(C2C-PAKE) protocol in a cross-realm setting. However, the current paper demonstrates that Kim et al.’s C2C-PAKE protocol is susceptible to a one-way man-in-the-middle attack and a password-compromise impersonation attack. Also, we presents an enhancement to resolve such problems.