ISSN ONLINE(2320-9801) PRINT (2320-9798)

All submissions of the EM system will be redirected to Online Manuscript Submission System. Authors are requested to submit articles directly to Online Manuscript Submission System of respective journal.

Research Article Open Access

An Efficient Two-Server Password Only Authenticated Key Exchange Secure Against Dictionary Attacks

Abstract

Password-authenticated key exchange(PAKE) is where a client and a server, who share a password, authenticate each other and meanwhile establish a crypto-graphic key by exchange of messages. In this, all the passwords necessary to authenticate clients are stored in a single server. If the server is compromised, due to, for example, hacking or even insider attacks, passwords stored in the server are all disclosed. In this paper, consider a scenario where two servers cooperate to authenticate a client and if one server is compromised, the attacker still cannot pretend to be the client with the information from the compromised server. Current solutions for two-server PAKE are either symmetric in the sense that two peer servers equally contribute to the authentication or asymmetric in the sense that one server authenticates the client with the help of another server. This paper presents asymmetric solution for two-server PAKE, where the client can establish different cryptographic keys with the two servers. Our protocol runs in parallel and is more efficient than existing symmetric two-server PAKE protocol and even more efficient than existing asymmetric two-server PAKE protocols in terms of parallel computation

Sonal C. Pansare, Prof.Vaishali Nandedkar

To read the full article Download Full Article | Visit Full Article