In 2006, Lu and Cao proposed an off-line password guessing attack on an efficient key agreement protocol for secure authentication. Lu and Cao pointed out that the Kim et al.’s protocol is vulnerable to the off-line password guessing attack. Therefore, they presented a modified protocol to avoid this attack. However, in this paper, we shall show that their modified protocol cannot resist the on-line password guessing attack.
Relation:
Journal of Discrete Mathematical Sciences & Cryptography 12(5):595–598