Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks

Joint Authors

Nam, Junghyun
Won, Dongho
Choo, Kim-Kwang Raymond
Paik, Juryon

Source

The Scientific World Journal

Issue

Vol. 2014, Issue 2014 (31 Dec. 2014), pp.1-15, 15 p.

Publisher

Hindawi Publishing Corporation

Publication Date

2014-09-18

Country of Publication

Egypt

No. of Pages

15

Main Subjects

Medicine
Information Technology and Computer Science

Abstract EN

While a number of protocols for password-only authenticated key exchange (PAKE) in the 3-party setting have been proposed, it still remains a challenging task to prove the security of a 3-party PAKE protocol against insider dictionary attacks.

To the best of our knowledge, there is no 3-party PAKE protocol that carries a formal proof, or even definition, of security against insider dictionary attacks.

In this paper, we present the first 3-party PAKE protocol proven secure against both online and offline dictionary attacks as well as insider and outsider dictionary attacks.

Our construct can be viewed as a protocol compiler that transforms any 2-party PAKE protocol into a 3-party PAKE protocol with 2 additional rounds of communication.

We also present a simple and intuitive approach of formally modelling dictionary attacks in the password-only 3-party setting, which significantly reduces the complexity of proving the security of 3-party PAKE protocols against dictionary attacks.

In addition, we investigate the security of the well-known 3-party PAKE protocol, called GPAKE, due to Abdalla et al.

(2005, 2006), and demonstrate that the security of GPAKE against online dictionary attacks depends heavily on the composition of its two building blocks, namely a 2-party PAKE protocol and a 3-party key distribution protocol.

American Psychological Association (APA)

Nam, Junghyun& Choo, Kim-Kwang Raymond& Paik, Juryon& Won, Dongho. 2014. Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks. The Scientific World Journal،Vol. 2014, no. 2014, pp.1-15.
https://search.emarefa.net/detail/BIM-1051087

Modern Language Association (MLA)

Nam, Junghyun…[et al.]. Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks. The Scientific World Journal No. 2014 (2014), pp.1-15.
https://search.emarefa.net/detail/BIM-1051087

American Medical Association (AMA)

Nam, Junghyun& Choo, Kim-Kwang Raymond& Paik, Juryon& Won, Dongho. Password-Only Authenticated Three-Party Key Exchange Proven Secure against Insider Dictionary Attacks. The Scientific World Journal. 2014. Vol. 2014, no. 2014, pp.1-15.
https://search.emarefa.net/detail/BIM-1051087

Data Type

Journal Articles

Language

English

Notes

Includes bibliographical references

Record ID

BIM-1051087