Gateway-oriented password-authenticated key exchange protocol in the standard model

  • Authors:
  • Fushan Wei;Zhenfeng Zhang;Chuangui Ma

  • Affiliations:
  • Department of Information Research, Zhengzhou Information Science and Technology Institute, Zhengzhou 450002, China and State Key Laboratory of Information Security, Institute of Software, Chinese ...;State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;Department of Information Research, Zhengzhou Information Science and Technology Institute, Zhengzhou 450002, China

  • Venue:
  • Journal of Systems and Software
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

A gateway-oriented password-based authenticated key exchange (GPAKE) is a 3-party protocol, which allows a client and a gateway to establish a common session key with the help of an authentication server. GPAKE protocols are suitable for mobile communication environments such as GSM (Global System for Mobile Communications) and 3GPP (The Third Generation Partnership Project). To date, most of the published protocols for GPAKE have been proven secure in the random oracle model. In this paper, we present the first provably-secure GPAKE protocol in the standard model. It is based on the 2-party password-authenticated key exchange protocol of Jiang and Gong. The protocol is secure under the DDH assumption (without random oracles). Furthermore, it can resist undetectable on-line dictionary attacks. Compared with previous solutions, our protocol achieves stronger security with similar efficiency.