RMIT University
Browse

Security analysis of Yang et al.'s practical password-based two-server authentication and key exchange system

conference contribution
posted on 2024-10-31, 17:54 authored by Xun YiXun Yi
Typical protocols for password-based authentication assumes a single server which stores all the passwords necessary to authenticate users. If the server is compromised, user passwords are disclosed. To address this issue, Yang et al. proposed a practical password-based two-server authentication and key exchange protocol, where a front-end server, keeping one share of a password, and a back-end server, holding another share of the password, cooperate in authenticating a user and, meanwhile, establishing a secret key with the user. In this paper, we present two "half-online and half-offline" attacks to Yang et al.'s protocol. By these attacks, user passwords can be determined once the backend server is compromised. Therefore, Yang et al.'s protocol has no essential difference from a password-based singleserver authentication protocol.

History

Start page

574

End page

578

Total pages

5

Outlet

4th International Conference on Network and System Security, NSS 2010

Name of conference

4th International Conference on Network and System Security, NSS 2010

Publisher

IEEE

Place published

United States

Start date

2010-09-01

End date

2010-09-03

Language

English

Copyright

© 2010 IEEE

Former Identifier

2006048459

Esploro creation date

2020-06-22

Fedora creation date

2015-01-14

Usage metrics

    Scholarly Works

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC