Return
Comments on EAKE-WC: Efficient and Anonymous Authenticated Key Exchange Scheme for Wearable Computing
DOI:10.1109/TMC.2024.3417181.png)
Abstract
En 中文
In the above paper, Tu et al. proposed an efficient and anonymous authenticated key exchange scheme optimized for wearable computing environments, utilizing lightweight cryptographic primitives like XOR, ASCON, and hash functions. They claimed the employed Authenticated Key Exchange (AKE) scheme is robust against prevalent security threats. However, our analysis reveal a critical vulnerability to replay attacks that could undermine the protocol's security; specifically, an attacker could intercept messages and induce unauthorized server-side password updates, effectively blocking further legitimate user communications. Upon dissecting the root causes of this vulnerability, we offer targeted recommendations to mitigate such attacks and reinforce the protocol's defenses.
Keywords:
Authentication Key Exchange (AKE)
replay attacks
security and privacy
wearable computing
Journal
IF:
9.2
Papers:
5.6K
Citations:
1.8W

