• Home
  • Search
  • Dictionary Attacks against Password-Based Authenticated Three-Party Key Exchange Protocols
  • Cite Icon19
  • https://doi.org/10.3837/tiis.2013.12.016Copy DOI Icon

Dictionary Attacks against Password-Based Authenticated Three-Party Key Exchange Protocols

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

A three-party password-based authenticated key exchange (PAKE) protocol allows two clients registered with a trusted server to generate a common cryptographic key from their individual passwords shared only with the server. A key requirement for three-party PAKE protocols is to prevent an adversary from mounting a dictionary attack. This requirement must be met even when the adversary is a malicious (registered) client who can set up normal protocol sessions with other clients. This work revisits three existing three-party PAKE protocols, namely, Guo et al.’s (2008) protocol, Huang’s (2009) protocol, and Lee and Hwang’s (2010) protocol, and demonstrates that these protocols are not secure against offline and/or (undetectable) online dictionary attacks in the presence of a malicious client. The offline dictionary attack we present against Guo et al.’s protocol also applies to other similar protocols including Lee and Hwang’s protocol. We conclude with some suggestions on how to design a three-party PAKE protocol that is resistant against dictionary attacks.

Similar Papers
  • Research Article
  • Citations4

Smooth Projective Hash Function From Codes and its Applications

  • Nov 01, 2022
  • IEEE Transactions on Services Computing
  • Masoumeh Koochak Shooshtari +1
  • Conference Article
  • Citations2

Gateway Threshold Password-based Authenticated Key Exchange Secure against Undetectable On-line Dictionary Attack

  • Jan 01, 2015
  • Yukou Kobayashi +6
  • Book Chapter
  • Citations2

IND-PCA Secure KEM Is Enough for Password-Based Authenticated Key Exchange (Short Paper)

  • Jan 01, 2017
  • Haiyang Xue +2
  • Research Article
  • Citations178

Password-based authenticated key exchange in the three-party setting

  • Jan 01, 2006
  • IEE Proceedings - Information Security
  • M Abdalla +2
  • Book Chapter
  • Citations46

Two-Round PAKE from Approximate SPH and Instantiations from Lattices

  • Jan 01, 2017
  • Jiang Zhang +1
  • Research Article

Instantiating the Hash-then-evaluate paradigm: Strengthening PRFs, PCFs, and OPRFs

  • Jan 01, 2025
  • Cryptography and Communications
  • Chris Brzuska +4
  • Book Chapter
  • Citations1

Key Exchange

  • Nov 30, 2022
  • Colin Boyd
  • Book Chapter
  • Citations43

Efficient and Provably Secure Generic Construction of Three-Party Password-Based Authenticated Key Exchange Protocols

  • Jan 01, 2006
  • Weijia Wang +1
  • PDF
  • Research Article
  • Citations7

Two-Round Password-Based Authenticated Key Exchange from Lattices

  • Dec 14, 2020
  • Wireless Communications and Mobile Computing
  • Anqi Yin +4
  • Conference Article
  • Citations2

Security of Indirect-Authenticated Key Exchange Protocol

  • Sep 01, 2009
  • Hsu-Hung Chia +3
  • Conference Article
  • Citations3

TW-KEAP

  • Nov 14, 2011
  • Wei-Kuo Chiang +1
  • Book Chapter
  • Citations18

Cryptanalysis of the N-Party Encrypted Diffie-Hellman Key Exchange Using Different Passwords

  • Jan 01, 2006
  • Raphael C -W Phan +1
  • Research Article
  • Citations17

Public‐key encryption indistinguishable under plaintext‐checkable attacks

  • Nov 01, 2016
  • IET Information Security
  • Michel Abdalla +2
  • Research Article

APPLICATION OF LAMPORT DIGITAL SIGNATURE SCHEME INTO THE STATION-TO-STATION PROTOCOL

  • Oct 01, 2022
  • Malaysian Journal of Computing
  • Md Nizam Udin +4
  • Research Article
  • Citations7

A Secure and Efficient Chaotic Maps Based Authenticated Key-Exchange Protocol for Smart Grid

  • Jun 24, 2017
  • Wireless Personal Communications
  • Majid Bayat +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.