International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 30 August 2013

Junghyun Nam, Kim-Kwang Raymond Choo, Juryon Paik, Dongho Won
ePrint Report ePrint Report
This note reports major previously unpublished security vulnerabilities in the password-only authenticated three-party key exchange protocol due to Lee and Hwang (Information Sciences, 180, 1702-1714, 2010): (1) the Lee-Hwang protocol is susceptible to a man-in-the-middle attack and thus fails to achieve implicit key authentication; (2) the protocol cannot protect clients\' passwords against an offline dictionary attack; and (3) the indistinguishability-based security of the protocol can be easily broken even in the presence of a passive adversary.

Expand

Additional news items may be found on the IACR news page.