We encounter new types of security problems in ad hoc networks because such
networks have little or no support infrastructure. In this paper we consid
er one such problem: a group of people in a meeting room do not have access
to public key infrastructure or third party key management service, and th
ey do not share any other prior electronic context. How can they set up a s
ecure session among their computers? We examine various alternatives and pr
opose new protocols for password-based multi-party key agreement in this sc
enario. Our protocols may be applicable in other scenarios, too. We also pr
esent a fault-tolerant version of a multi-party Diffie-Hellman key agreemen
t protocol which can be of independent interest. (C) 2000 Elsevier Science
B.V. All rights reserved.