arXiv · 1001.2945
Weakness Analysis and Improvement of a Gateway-Oriented Password-Based Authenticated Key Exchange Protocol
Abstract
Recently, Abdalla et al. proposed a new gateway-oriented password-based authenticated key exchange (GPAKE) protocol among a client, a gateway, and an authentication server, where each client shares a human-memorable password with a trusted server so that they can resort to the server for authentication when want to establish a shared session key with the gateway. In the letter, we show that a malicious client of GPAKE is still able to gain information of password by performing an undetectable on-line password guessing attack and can not provide the implicit key confirmation. At last, we present a countermeasure to against the attack.
Explore related subjects
Keep this discovery
He Debiao, Chen Jianhua, Hu Jin. 2010-01-18. Weakness Analysis and Improvement of a Gateway-Oriented Password-Based Authenticated Key Exchange Protocol. https://arxiv.org/abs/1001.2945
Cite the original work for its findings. Save a collection to share your selection of sources.