A New Cross-Realm Client-to-Client Password-Authentication Key Exchange Protocol
نویسندگان
چکیده
A cross-realm client-to-client password-authenticated key exchange (CR-C2C-PAKE) protocol provides a method of key exchange based on password-authenticated between clients registered in different servers. Our proposed CR-C2C-PAKE protocol can be implemented in secret-key setting. It can resist all types of known attacks including the password-compromise impersonation attack. We use common storage devices to complete mutual authentication between client and server in the same realm instead of the expensive smart cards. After the client-server's authentication process, we also use Kerberos system to support cross-realm secure authentication between servers in different realms. At last, the clients with different passwords can establish a secure session key under the help of their respective servers. Our new practical and secure protocol reserves all the advantages of the protocol using smart cards, including that the server only need to keep a secret number instead of the traditional password-tables to authenticate their clients with lower risk and cost. Furthermore, the clients in our protocol could change their passwords off-line anytime and anywhere. Security analysis will be given under the discrete logarithm and Diffie-Hellman assumptions.
منابع مشابه
A New Security Model for Cross-Realm C2C-PAKE Protocol
Cross realm client-to-client password authenticated key exchange (C2C-PAKE) schemes are designed to enable two clients in different realms to agree on a common session key using different passwords. In 2006, Yin-Bao presented the first provably secure cross-realm C2C-PAKE, which security is proven rigorously within a formally defined security model and based on the hardness of some computationa...
متن کاملClient-to-client Password-Based Authenticated Key Establishment in a Cross-Realm Setting
The area of password-based authenticated key establishment protocols has been the subject of a vast amount of work in the last few years due to its practical aspects. Despite the attention given to it, most passwordauthenticated key establishment (PAKE) schemes in the literature consider authentication between a client and a sever. Although some of them are extended to a threeparty PAKE protoco...
متن کاملEfficient and Provably Secure Client-to-Client Password-Based Key Exchange Protocol
We study client-to-client password-authenticated key exchange (C2C-PAKE) enabling two clients in different realms to agree on a common session key using different passwords. Byun et al. first presented C2C-PAKE schemes under the cross-realm setting. However, the schemes were not formally treated, and subsequently found to be flawed. In addition, in the schemes, there are still rooms for improve...
متن کاملEmploying Secure and Efficient Password-Authenticated Key Exchange in Wireless Networks
The password-authenticated key exchange (PAKE) is an important tool to secure wireless communications. To counter possible malicious attacks in wireless communications, this paper develops a stronger new cross-realm client-to-client (C2C) PAKE protocol based on the smart card framework agreement. Employing the client passwords, smart card information and server private keys, the new PAKE protoc...
متن کاملPassword-Authenticated Key Exchange between Clients in a Cross-Realm Setting
The area of password-based authenticated key exchange protocols has been the subject of a vast amount of work in the last few years due to its practical aspects. AuthA is an example of such a technology considered for standardization by the IEEE P1363.2 working group. Unfortunately in its current form AuthA, including some variants, only considered the classic client and server (2-party) scenar...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2010