A New Cross-Realm Client-to-Client Password-Authentication Key Exchange Protocol

نویسندگان

  • Xuelei LI
  • Fengtong WEN
  • Jiangning CUI
چکیده

A cross-realm client-to-client password-authenticated key exchange (CR-C2C-PAKE) protocol provides a method of key exchange based on password-authenticated between clients registered in different servers. Our proposed CR-C2C-PAKE protocol can be implemented in secret-key setting. It can resist all types of known attacks including the password-compromise impersonation attack. We use common storage devices to complete mutual authentication between client and server in the same realm instead of the expensive smart cards. After the client-server's authentication process, we also use Kerberos system to support cross-realm secure authentication between servers in different realms. At last, the clients with different passwords can establish a secure session key under the help of their respective servers. Our new practical and secure protocol reserves all the advantages of the protocol using smart cards, including that the server only need to keep a secret number instead of the traditional password-tables to authenticate their clients with lower risk and cost. Furthermore, the clients in our protocol could change their passwords off-line anytime and anywhere. Security analysis will be given under the discrete logarithm and Diffie-Hellman assumptions.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A New Security Model for Cross-Realm C2C-PAKE Protocol

Cross realm client-to-client password authenticated key exchange (C2C-PAKE) schemes are designed to enable two clients in different realms to agree on a common session key using different passwords. In 2006, Yin-Bao presented the first provably secure cross-realm C2C-PAKE, which security is proven rigorously within a formally defined security model and based on the hardness of some computationa...

متن کامل

Client-to-client Password-Based Authenticated Key Establishment in a Cross-Realm Setting

The area of password-based authenticated key establishment protocols has been the subject of a vast amount of work in the last few years due to its practical aspects. Despite the attention given to it, most passwordauthenticated key establishment (PAKE) schemes in the literature consider authentication between a client and a sever. Although some of them are extended to a threeparty PAKE protoco...

متن کامل

Efficient and Provably Secure Client-to-Client Password-Based Key Exchange Protocol

We study client-to-client password-authenticated key exchange (C2C-PAKE) enabling two clients in different realms to agree on a common session key using different passwords. Byun et al. first presented C2C-PAKE schemes under the cross-realm setting. However, the schemes were not formally treated, and subsequently found to be flawed. In addition, in the schemes, there are still rooms for improve...

متن کامل

Employing Secure and Efficient Password-Authenticated Key Exchange in Wireless Networks

The password-authenticated key exchange (PAKE) is an important tool to secure wireless communications. To counter possible malicious attacks in wireless communications, this paper develops a stronger new cross-realm client-to-client (C2C) PAKE protocol based on the smart card framework agreement. Employing the client passwords, smart card information and server private keys, the new PAKE protoc...

متن کامل

Password-Authenticated Key Exchange between Clients in a Cross-Realm Setting

The area of password-based authenticated key exchange protocols has been the subject of a vast amount of work in the last few years due to its practical aspects. AuthA is an example of such a technology considered for standardization by the IEEE P1363.2 working group. Unfortunately in its current form AuthA, including some variants, only considered the classic client and server (2-party) scenar...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010