Search engine for discovering works of Art, research articles, and books related to Art and Culture
ShareThis
Javascript must be enabled to continue!

Security Analysis of Password-based Authenticated Key Exchange Protocols

View through CrossRef
Abstract Password-based cryptosystems commonly suffer from dictionary attacks because their security depends on low entropy passwords. It is ever challenging to design a password-based cryptosystem secure against this attack. Password-based authenticated key exchange (PAKE) protocols allow two or more interacting parties to establish cryptographic keys based on their knowledge of some password. The PAKE protocols commonly use password-based encryption and are therefore susceptible to dictionary attacks. Many existing PAKE protocols are claimed to be secure against these dictionary attacks but there is no easy method to verify their claim. In this work we focus on evaluating the security of two-party PAKE protocols under possible attack scenarios. We first consider all possible combination of participants of an attack scenario, which turn out to be 5 in number. This gives rise to 25 possible attack scenarios among the participants. We find that 11 out of these 25 scenarios are valid. We then analyze the security of 5 PAKE protocols under the attack scenarios developed by us. Namely, we analyze EKE, SPEKE, SRP, KOY and IdBP protocols. We also provide some suggestions on improving existing PAKE designs.
Title: Security Analysis of Password-based Authenticated Key Exchange Protocols
Description:
Abstract Password-based cryptosystems commonly suffer from dictionary attacks because their security depends on low entropy passwords.
It is ever challenging to design a password-based cryptosystem secure against this attack.
Password-based authenticated key exchange (PAKE) protocols allow two or more interacting parties to establish cryptographic keys based on their knowledge of some password.
The PAKE protocols commonly use password-based encryption and are therefore susceptible to dictionary attacks.
Many existing PAKE protocols are claimed to be secure against these dictionary attacks but there is no easy method to verify their claim.
In this work we focus on evaluating the security of two-party PAKE protocols under possible attack scenarios.
We first consider all possible combination of participants of an attack scenario, which turn out to be 5 in number.
This gives rise to 25 possible attack scenarios among the participants.
We find that 11 out of these 25 scenarios are valid.
We then analyze the security of 5 PAKE protocols under the attack scenarios developed by us.
Namely, we analyze EKE, SPEKE, SRP, KOY and IdBP protocols.
We also provide some suggestions on improving existing PAKE designs.

Related Results

Password Manager
Password Manager
This project presents a Password Manager, a secure web-based application developed to help users store and manage their passwords safely. Many people still use weak or repeated pas...
User-Centric Adaptive Password Policies to Combat Password Fatigue
User-Centric Adaptive Password Policies to Combat Password Fatigue
Today, online users will have an average of 25 password-protected accounts online, yet use, on average, 6.5 passwords. The excessive cognitive burden of remembering large amounts o...
A Novel Session Password Security Technique using Textual Color and Images
A Novel Session Password Security Technique using Textual Color and Images
Abstract Traditionally people will be using a weak password that has to be often changed can be influenced by a dictionary attack, shoulder surfing, and other met...
Efficient Plain Password Cryptanalysis Techniques
Efficient Plain Password Cryptanalysis Techniques
In this research work, some low complexity and efficient cryptanalysis approaches are proposed to decrypt password (encryption keys). Passwords are still one of the most common mea...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
Graphical Password Authentication System In Terms of Usability and Security Attribute
Graphical Password Authentication System In Terms of Usability and Security Attribute
In today's digital era, safeguarding computer systems and information is a paramount challenge. The primary goal is to ensure that only authorized individuals have access to the sy...
Survey Paper on Graphical Password Authentication System In Terms of Usability and Security Attribute
Survey Paper on Graphical Password Authentication System In Terms of Usability and Security Attribute
In today's digital era, safeguarding computer systems and information is a paramount challenge The primary goal is to ensure that only authorized individuals have access to the sys...
Aplikasi Pengukuran Kekuatan dan Rekomendasi Password Berdasarkan Input Pengguna dengan Metode Entropi
Aplikasi Pengukuran Kekuatan dan Rekomendasi Password Berdasarkan Input Pengguna dengan Metode Entropi
Penelitian ini mengembangkan aplikasi berbasis Python untuk mengevaluasi kekuatan password serta memberikan rekomendasi password yang lebih aman menggunakan alfabet fonetik NATO, T...

Back to Top