International Association for Cryptologic Research

International Association
for Cryptologic Research

IACR News item: 24 October 2013

Junghyun Nam, Kim-Kwang Raymond Choo, Juryon Paik, Dongho Won
ePrint Report ePrint Report
Despite all the research efforts made so far, the design of protocols for password-authenticated key exchange (PAKE) still remains a non-trivial task. One of the major challenges in designing such protocols is to protect low-entropy passwords from the notorious dictionary attacks. In this work, we revisit Abdalla and Pointcheval\'s three-party PAKE protocol presented in Financial Cryptography 2005, and demonstrate that the protocol is vulnerable to an off-line dictionary attack whereby a malicious client can find out the passwords of other clients.

Expand

Additional news items may be found on the IACR news page.