[Resource Topic] 2013/666: An Offline Dictionary Attack against a Three-Party Key Exchange Protocol

Welcome to the resource topic for 2013/666

Title:
An Offline Dictionary Attack against a Three-Party Key Exchange Protocol

Authors: Junghyun Nam, Kim-Kwang Raymond Choo, Juryon Paik, Dongho Won

Abstract:

Despite all the research efforts made so far, the design of protocols for password-authenticated key exchange (PAKE) still remains a non-trivial task. One of the major challenges in designing such protocols is to protect low-entropy passwords from the notorious dictionary attacks. In this work, we revisit Abdalla and Pointcheval’s three-party PAKE protocol presented in Financial Cryptography 2005, and demonstrate that the protocol is vulnerable to an off-line dictionary attack whereby a malicious client can find out the passwords of other clients.

ePrint: https://eprint.iacr.org/2013/666

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .