• DocumentCode
    3629092
  • Title

    A password-based key establishment protocol with symmetric key cryptography

  • Author

    Imran Erguler;Emin Anarim

  • Author_Institution
    Bo?azi?i ?niversitesi Elektrik-Elektronik, M?hendisli?i B?l?m?, ?stanbul, Turkey
  • fYear
    2008
  • fDate
    4/1/2008 12:00:00 AM
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    In 2005, Laih, Ding and Huang proposed a password-based key establishment protocol such that a user and a server can authenticate each other and generate a strong session key by their shared weak password within a symmetric cipher in an insecure channel. They claim that the proposed protocol is secure against offline dictionary attacks that are major threats for most of the weak password-based protocols and other some well known attacks. However Tang and Mitchell shows that the protocol suffers from an offline dictionary attack requiring a machine-based search of size 223 which takes only about 2.3 hours. So designing such a protocol with providing practical security against offline attack is still an open problem. In this study, we introduce two password-based authenticated key establishment protocols that provide practical security against offline dictionary attacks by only using symmetric cryptography.
  • Keywords
    "Protocols","Dictionaries","Cryptography","Security","Art","Servers"
  • Publisher
    ieee
  • Conference_Titel
    Signal Processing, Communication and Applications Conference, 2008. SIU 2008. IEEE 16th
  • ISSN
    2165-0608
  • Print_ISBN
    978-1-4244-1998-2
  • Type

    conf

  • DOI
    10.1109/SIU.2008.4632635
  • Filename
    4632635