Denial-of-service (DoS) attack is one of the most malicious Internet-based attacks. Introduction of cryptographic authentication
protocols into Internet environment does not help alleviate the impact of denial-of-service attacks, but rather increases
the vulnerability to the attack because of the heavy computation associated with cryptographic operation. Nevertheless, many
Internet security protocols including SSL/TLS protocol do not consider this aspect. We consider this overlooked issue in authentication
protocol design, and propose an effective countermeasure applicable to authentication protocols like SSL/TLS protocol which
adopt public-key based encryption to authenticate the server to the client.