Authentication using minimally trusted servers

A number of key distribution protocols using multiple authentication servers, where a minority of them may be untrustworthy, have recently been proposed. This paper analyses the problem of key distribution using minimally trusted multiple servers, and presents a new protocol. In this protocol, as long as all servers do not collude to defraud the clients, either a session key (not known to any server) is successfully established, or the protocol fails in such a way that the clients are aware that it has failed, i.e. the protocol works in a situation where the servers are 'minimally trusted'.