Informatica logo


Login Register

  1. Home
  2. Issues
  3. Volume 17, Issue 4 (2006)
  4. On the Security Analysis of Lee, Hwang & ...

Informatica

Information Submit your article For Referees Help ATTENTION!
  • Article info
  • Related articles
  • Cited by
  • More
    Article info Related articles Cited by

On the Security Analysis of Lee, Hwang & Lee (2004) and Song & Kim (2000) Key Exchange / Agreement Protocols
Volume 17, Issue 4 (2006), pp. 467–480
Kim-Kwang Raymond Choo  

Authors

 
Placeholder
https://doi.org/10.15388/Informatica.2006.149
Pub. online: 1 January 2006      Type: Research Article     

The views and opinions expressed in this paper do not necessarily reflect those of the Commonwealth Government, the Minister for Justice and Customs, or the Australian Institute of Criminology. Research was performed while the author was with the Information Security Institute / Queensland University of Technology.

Received
1 May 2005
Published
1 January 2006

Abstract

We revisit the password-based group key exchange protocol due to Lee et al. (2004), which carries a claimed proof of security in the Bresson et al. model under the intractability of the Decisional Diffie–Hellman problem (DDH) and Computational Diffie–Hellman (CDH) problem. We reveal a previously unpublished flaw in the protocol and its proof, whereby we demonstrate that the protocol violates the definition of security in the model. To provide a better insight into the protocol and proof failures, we present a fixed protocol. We hope our analysis will enable similar mistakes to be avoided in the future. We also revisit protocol 4 of Song and Kim (2000), and reveal a previously unpublished flaw in the protocol (i.e., a reflection attack).

Related articles Cited by PDF XML
Related articles Cited by PDF XML

Copyright
No copyright data available.

Keywords
password-based key establishment protocols key agreement protocols provable security information security

Metrics
since January 2020
670

Article info
views

0

Full article
views

461

PDF
downloads

206

XML
downloads

Export citation

Copy and paste formatted citation
Placeholder

Download citation in file


Share


RSS

INFORMATICA

  • Online ISSN: 1822-8844
  • Print ISSN: 0868-4952
  • Copyright © 2023 Vilnius University

About

  • About journal

For contributors

  • OA Policy
  • Submit your article
  • Instructions for Referees
    •  

    •  

Contact us

  • Institute of Data Science and Digital Technologies
  • Vilnius University

    Akademijos St. 4

    08412 Vilnius, Lithuania

    Phone: (+370 5) 2109 338

    E-mail: informatica@mii.vu.lt

    https://informatica.vu.lt/journal/INFORMATICA
Powered by PubliMill  •  Privacy policy