English

Weakness Analysis and Improvement of a Gateway-Oriented Password-Based Authenticated Key Exchange Protocol

Cryptography and Security 2010-01-19 v1

Abstract

Recently, Abdalla et al. proposed a new gateway-oriented password-based authenticated key exchange (GPAKE) protocol among a client, a gateway, and an authentication server, where each client shares a human-memorable password with a trusted server so that they can resort to the server for authentication when want to establish a shared session key with the gateway. In the letter, we show that a malicious client of GPAKE is still able to gain information of password by performing an undetectable on-line password guessing attack and can not provide the implicit key confirmation. At last, we present a countermeasure to against the attack.

Keywords

Cite

@article{arxiv.1001.2945,
  title  = {Weakness Analysis and Improvement of a Gateway-Oriented Password-Based Authenticated Key Exchange Protocol},
  author = {He Debiao and Chen Jianhua and Hu Jin},
  journal= {arXiv preprint arXiv:1001.2945},
  year   = {2010}
}

Comments

6 pages

R2 v1 2026-06-21T14:35:52.664Z