Forward Secrecy of SPAKE2.

José Becerra, Dimiter Ostrev, Marjan Škrobot · IACR Cryptology ePrint Archive · 2019

Currently, the Simple Password-Based Encrypted Key Exchange (SPAKE2) protocol of Abdalla and Pointcheval (CT-RSA 2005) is being considered by the IETF for standardization and integration in TLS 1.3. Although it has been proven secure in the Find-then-Guess model of Bellare, Pointcheval and Rogaway (EUROCRYPT 2000), whether it satisfies some notion of forward secrecy remains an open question.

Read the paper · More papers on PaperTik