Analysis of the SPEKE password-authenticated key exchange protocol
Analysis of the SPEKE password-authenticated key exchange protocol
复制标题
SPEKE密码认证密钥交换协议分析
DOI:
--
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
Muxiang Zhang
中科院分区:
文献类型:
--
作者:
Muxiang Zhang
In this letter, we show that for the SPEKE password-authenticated key exchange protocol, an adversary is able to test multiple possible passwords using a single impersonation attempt. In particular, when passwords are short Personal Identification Numbers (PINs), we show that a fully-constrained SPEKE is susceptible to password guessing attack. Our analysis contradicts the claim that the SPEKE protocol appears to be at least as strong as the Bellovin-Merritt EKE protocol. For EKE, an adversary can gain information about at most one possible password in each impersonation attempt.