13th Pacific Rim International Symposium on Dependable Computing (PRDC 2007)
An Efficient Client-to-Client Password-Authenticated Key Exchange Resilient to Server Compromise
Melbourne, Victoria, Australia
December 17-December 19
ISBN: 0-7695-3054-0
With rapid changes in the modern communication environment such as ad hoc networks and ubiquitous computing, it is necessary to construct a secure endto-end channel between clients. The fundamental security goal of PAKE is security against dictionary attacks. The protocols for verifier-based PAKE are additionally required to be secure against server compromise. This paper presents a new password authentication and key-exchange protocol suitable for client-to-client without a server public key in different realms to agree on a common session key using different passwords over an untrusted network. The proposed protocol's security, simplicity, and speed make it ideal for a wide range of real-world applications in which secure password authentication is required.
Citation:
Hongfeng Zhu, Tianhua Liu, Jie Liu, Guiran Chang, "An Efficient Client-to-Client Password-Authenticated Key Exchange Resilient to Server Compromise," prdc, pp.405-408, 13th Pacific Rim International Symposium on Dependable Computing (PRDC 2007), 2007