Cryptanalysis of Two Password Authenticated Key Exchange Protocols Based on RSA

Tianjie Cao,Dongdai Lim
DOI: https://doi.org/10.1109/lcomm.2006.1665131
IF: 3.5529
2006-01-01
IEEE Communications Letters
Abstract:In 2002, Zhu et al. proposed a password-based authenticated key exchange protocol based on RSA. Many researchers pointed out that Zhu et al.'s protocol is vulnerable to off-line dictionary attack. In 2003, Yeh et al. proposed an improved protocol. Recently, Lo and Yang-Wang pointed out that Yeh et al.'s improved protocol is also vulnerable to offline dictionary attack. To avoid this weakness existed in Yeh et al.'s protocol, Lo and Yang-Wang proposed two improved protocols. However, in this letter, we show that the Lo protocol is vulnerable to an active off-line dictionary attack and the Yang-Wang protocol is vulnerable to a passive off-line dictionary attack
What problem does this paper attempt to address?