Title :
A password-based key establishment protocol with symmetric key cryptography
Author :
Imran Erguler;Emin Anarim
Author_Institution :
Bo?azi?i ?niversitesi Elektrik-Elektronik, M?hendisli?i B?l?m?, ?stanbul, Turkey
fDate :
4/1/2008 12:00:00 AM
Abstract :
In 2005, Laih, Ding and Huang proposed a password-based key establishment protocol such that a user and a server can authenticate each other and generate a strong session key by their shared weak password within a symmetric cipher in an insecure channel. They claim that the proposed protocol is secure against offline dictionary attacks that are major threats for most of the weak password-based protocols and other some well known attacks. However Tang and Mitchell shows that the protocol suffers from an offline dictionary attack requiring a machine-based search of size 223 which takes only about 2.3 hours. So designing such a protocol with providing practical security against offline attack is still an open problem. In this study, we introduce two password-based authenticated key establishment protocols that provide practical security against offline dictionary attacks by only using symmetric cryptography.
Keywords :
"Protocols","Dictionaries","Cryptography","Security","Art","Servers"
Conference_Titel :
Signal Processing, Communication and Applications Conference, 2008. SIU 2008. IEEE 16th
Print_ISBN :
978-1-4244-1998-2
DOI :
10.1109/SIU.2008.4632635