January 1, 2014· IACR Cryptology ePrint Archive
conference-paper
Open access
Security analysis of J-PAKE
Authors:Mohsen Toorani *
Abstract
J-PAKE is a Password-Authenticated Key Exchange protocol, proposed in 2008 and presented again in 2010 and 2011. It does not require any public key infrastructure but uses zero-knowledge proofs. J-PAKE has been submitted as a candidate for the IEEE P1363.2 standard for password-based public key cryptography, and included in OpenSSL and OpenSSH. Since December 2010, J-PAKE has been used in Mozilla Firefox web browser. In this paper, we show that J-PAKE is vulnerable to password compromise impersonation attack, replay attack, and unknown key-share attack. We also propose some improvements for thwarting replay and unknown key-share attacks.
Community
0 commentsUse Connect Wallet in the navigation
No discussion yet
Be the first to share a question or observation.