Credential Authenticated Identication and Key Exchange
Jan L. Camenisch, Nathalie Casati, Thomas Groß, Victor Shoup · 2013
This paper initiates a study of two-party identication and key-exchange protocols in which users authenticate themselves by prov- ing possession of credentials satisfying arbitrary policies, instead of using the more traditional mechanism of a public-key infrastructure. Deni- tions in the universal composability framework are given, and practical protocols satisfying these denitions, for policies of practical interest, are presented. All protocols are analyzed in the common reference string model, assuming adaptive corruptions with erasures, and no random or- acles. The new security notion includes password-authenticated key ex- change as a special case, and new, practical protocols for this problem are presented as well, including the rst such protocol that provides re- silience against server compromise (without random oracles).