最近几年很多基于口令的三因素密钥交换被提了出来。2010年Chang等人提出一种基于口令的三方密钥交换协议,并对其进行证明,宣称其是一种安全高效的密钥交换协议。对Chang等人提出的协议进行介绍,并进行安全分析,证明其不能抵抗离线典攻击。然后对Chang等人提出的协议进行改进,使其能够抵抗离线字典攻击。对改进的协议进行安全分析。
In recent years, a lot of three factor key exchange based on password is proposed. In 2010, Chang et al proposed a three party key exchange protocol based on password, which was proved to be a safe and efficient key exchange protocol. Introduce the protocol proposed by Chang et al., and carries out security analysis. It is proved that it cannot resist the off code attack. Then the protocol of Chang et al is improved, which can resist the off-line dictionary attack. Presents the security analysis of the improved protocol.