Password-Authenticated Key (PAK) Diffie-Hellman Exchange
Alec Brusilovsky, Igor Faynberg, Zachary Zeltsan, S. Patel · 2010
This document proposes to add mutual authentication, based on a human-memorizable password, to the basic, unauthenticated Diffie-Hellman key exchange.The proposed algorithm is called the Password-Authenticated Key (PAK) exchange.PAK allows two parties to authenticate themselves while performing the Diffie-Hellman exchange.The protocol is secure against all passive and active attacks.In particular, it does not allow either type of attacker to obtain any information that would enable an offline dictionary attack on the password.PAK provides Forward Secrecy.