Comment on'Robust and efficient password authenticated key agreement with user anonymity for session initiation protocol-based communications'.

dc.contributor.authorChaudhry, Shehzad Ashraf
dc.date.accessioned2022-12-27T06:57:50Z
dc.date.accessioned2023-08-19T08:19:45Z
dc.date.available2022-12-27T06:57:50Z
dc.date.available2023-08-19T08:19:45Z
dc.date.issued2015-05
dc.description.abstractI am writing this comment with reference to an article published recently by Zhang et al. [1] in IET communications. The Zhang et al.’s protocol for SIP authentication is robust against all known attacks, further it provide user anonymity. They have alternated the need of storing verification tables to reduce storage and computation burden on SIP server, but I am worried about the correctness of their protocol as during authentication phase the client sends W = r1, R = r1(h(PW||c) ⊕ h(username||c))s2 P and V = Em(r1 P||h(PW||c) ⊕ h(username||c)||T ). Upon receiving W and V the SIP server computes m = (s −1 ) 2 W and decrypts V by using key m. Then server extracts (h(PW||c) ⊕ h(username||c)) from both W and V independently, further server compare both values of (h(PW||c) ⊕ h(username||c)), if they are equivalent server continues the authentication process. My concern is the server got user’s password PW, name username and a random number c protected by one way hash function. The user name or password is not even revealed to the server. Hence the user is not recognised by the server, so how can the user be able to obtain user specific services from the server? The authors need to either clarify the protocol or propose an enhanced protocol in order to make server able to recognise the user who has initiated the login request, at the moment protocol cannot distinguish between two different legal users say Ui and Uj.en_US
dc.identifier.citationChaudhry, S. A. (2015). Comment on'Robust and efficient password authenticated key agreement with user anonymity for session initiation protocol-based communications'. IET Commun., 9(7), 1034.en_US
dc.identifier.doihttps://doi.org/10.1049/iet-com.2014.1082
dc.identifier.urihttps://edms.wexl.in/handle/1/4205
dc.language.isoenen_US
dc.publisherIET Communicationsen_US
dc.subjectRobusten_US
dc.subjectAuthenticated key agreementen_US
dc.subjectProtocolen_US
dc.subjectBased communicationsen_US
dc.titleComment on'Robust and efficient password authenticated key agreement with user anonymity for session initiation protocol-based communications'.en_US
dc.title.alternativeJournal articleen_US
dc.typeArticleen_US

Files

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: