Research & Reviews: A Journal of Embedded System & Applications

Enhanced of Simple Three Party Key Exchange Protocol: Attacks and a Solution

  1. H. K. Pathak
  2. Manju Sanghi

Abstract

In secure communication password based three party encrypted key exchange (3PEKE) protocols have become significant due to the simplicity of maintaining human memorable passwords. In 2007, Lu and Cao proposed a simple and efficient three party password based authenticated key exchange (S-3PAKE) protocol. In 2008, Guo et al. found that S-3PAKE protocol has some loop holes and attacked by man in the middle attack and on-line dictionary attack. They proposed an improved protocol by which two side users individually implement 2-PAKE protocol to obtain message authentication codes (MAC) prior to creating a shared session key. Recently, Yang et al. proposed an effective 3PAKE protocol without requiring the execution of 2 PAKE protocol. In this paper, we demonstrate that Yang et al.'s protocol is vulnerable to undetectable on-line password guessing attacks and off-line password guessing attacks. Besides, we also propose a new three party EKE protocol  which not only is secure against the guessing attacks but also satisfies the formal security   proof by AVISPA.

Keywords

Support