Cryptanalysis on Lu-Cao's Key Exchange Protocol

Lu-Cao 패스워드기반 키 교환 프로토콜의 안전성 분석

  • 윤택영 (고려대학교 정보경영공학전문대학원) ;
  • 조성민 (고려대학교 정보경영공학전문대학원) ;
  • 박영호 (세종 사이버대학교)
  • Published : 2008.08.29

Abstract

Recently, Lu and Cao proposed a password-authenticated key exchange protocol in the three party setting, and the authors claimed that their protocol works within three rounds. In this paper, we analyze the protocol and show the protocol cannot work within three rounds. We also find two security flaws in the protocol. The protocol is vulnerable to an undetectable password guessing attack and an off-line password guessing attack.

Keywords