In recent years, a lot of three factor key exchange based on password is proposed. In 2010, Chang et al proposed a three party key exchange protocol based on password, which was proved to be a safe and efficient key exchange protocol. Introduce the protocol proposed by Chang et al., and carries out security analysis. It is proved that it cannot resist the off code attack. Then the protocol of Chang et al is improved, which can resist the off-line dictionary attack. Presents the security analysis of the improved protocol.