Abstract
A deniable authentication protocol is used to identify the source of a received message for a receiver, but the receiver is unable to prove to a third party the source of the received message. Recently, Fan et al. proposed a deniable authentication protocol based on Diffie-Hellman algorithm. In this paper, we show that Fan et al.'s protocol does not possess the deniable properly as they claimed. A cheating receiver can prove the source of the received message to a third party. In addition, we also present a modification of Fan et al.'s protocol to overcome the security flaw.