Efficient Three-Party Authentication and Key Agreement Protocols Resistant to Password Guessing Attacks

Her-tyan Yeh,Hung-min Sun,Tzonelih Hwang
DOI: https://doi.org/10.6688/jise.2003.19.6.6
2003-01-01
Journal of information science and engineering
Abstract:Three-party EKE was proposed to establish a session key between two clients through a server. However, three-party EKE is insecure against undetectable on-line and off-line password guessing attacks. In this paper, we first propose an enhanced three-party EKE to withstand the security risk in three-party EKE. We also propose a verifier-based three-party EKE that is more secure than a plaintext-equivalent mechanism in which a compromise of the server's database will not result in success in directly impersonating clients.
What problem does this paper attempt to address?