Journal of Beijing University of Posts and Telecommunications

  • EI核心期刊

JOURNAL OF BEIJING UNIVERSITY OF POSTS AND TELECOM ›› 2010, Vol. 33 ›› Issue (6): 64-67.doi: 10.13190/jbupt.201006.64.fanyj

• Papers • Previous Articles     Next Articles

A PasswordBased Authenticated Key Exchange  Protocol for MobileCommerce Environments

  

  • Received:2010-03-31 Revised:2010-06-23 Online:2010-12-28 Published:2011-01-07
  • Contact: Fan Ya-Jun E-mail:bestfyj@163.com

Abstract:

For mobilecommerce environments, a novel passwordbased authenticated key exchange protocol is proposed to solve that the technology to effectively prevent legitimate users’ abuse, named as completely automatic public Turing test to tell computer and human apart (CAPTCHA), is vulnerable to analytical attacks. The protocol elaborately combines the CAPTCHA challenge/response progress with the authenticated key exchange interaction. It introduces symmetric encryption scheme to make CAPTCHA secure without additional communication rounds. And it is based on smartcards to obtain stronger security and adopts elliptic curve cryptosystem which is suitable for the environments. In random oracle model it is provably secure. Compared with the other related protocols, it requires only three communication rounds, protects CAPTCHA against analytical attacks, needs no validation tables storing on the server and provides perfect forward secrecy.

Key words: passwordbased authenticated key exchange, completely automatic public Turing test to tell computer and human apart, elliptic curve cryptosystem, smart card