The invention discloses a three-party
password-based
authenticated key exchange protocol in no need of a
smart card. The method comprises the following steps: A, in an initialization stage, a
server Sinitializes certain parameters and publishes the parameters {p, alpha, h1(.), IDS and Ts(alpha)}, wherein Ts(alpha) is used as the public key of the S, the s is used as the private key of the S and the two keys are stored in a
database, and the protocol does not need a
smart card; B, in a registration stage, is a legal user Ui wants to register the self information to the
server S, a registrationrequest is firstly initiated; C,
authenticated key exchange is carried out; and D, in a
password exchange stage, when a user A feels that the current
password may be or is already leaked out, a new password needs to be exchanged in order to reduce unnecessary losses. The unsafe problems, such as disclosure and theft of information between two parties in
the Internet communication, can be solved,the
authenticated key exchange purposes are realized in the communication process with no need of assistance of the
smart card, and the higher performance and the higher efficiency are realized in a similar safety protocol.