arrow
Return

Comments on EAKE-WC: Efficient and Anonymous Authenticated Key Exchange Scheme for Wearable Computing

delete2024-12-01
delete0
PRE
AI
W
Weizheng Wang
Z
Zhaoyang Han *
C
Chunhua Su
DOI:10.1109/TMC.2024.3417181delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In the above paper, Tu et al. proposed an efficient and anonymous authenticated key exchange scheme optimized for wearable computing environments, utilizing lightweight cryptographic primitives like XOR, ASCON, and hash functions. They claimed the employed Authenticated Key Exchange (AKE) scheme is robust against prevalent security threats. However, our analysis reveal a critical vulnerability to replay attacks that could undermine the protocol's security; specifically, an attacker could intercept messages and induce unauthorized server-side password updates, effectively blocking further legitimate user communications. Upon dissecting the root causes of this vulnerability, we offer targeted recommendations to mitigate such attacks and reinforce the protocol's defenses.
Keywords:
Authentication Key Exchange (AKE)
replay attacks
security and privacy
wearable computing

Journal

IEEE Transactions on Mobile Computing cover
IEEE Transactions on Mobile Computing
IF:
9.2
Papers:
5.6K
Citations:
1.8W

Organization

N
Nanjing Forestry University
Scholars:
2.0W
Papers: 1.6W
Citations: 3.2W
C
City University of Hong Kong
Scholars:
2.3W
Papers: 3.0W
Citations: 6.1W
U
University of Aizu
Scholars:
768
Papers: 1.0K
Citations: 302
researcher View more organizations