Tightly-Secure Authenticated Key Exchange, Revisited.

Tibor Jager, Eike Kiltz, Doreen Riepel, Sven Schäge · IACR Cryptology ePrint Archive · 2020

We introduce new tightly-secure authenticated key exchange (AKE) protocols that are extremely efficient, yet have only a constant security loss and can be instantiated in the random oracle model both from the standard DDH assumption and a subgroup assumption over RSA groups. These protocols can be deployed with optimal parameters, independent of the number of users or sessions, without the need to compensate a security loss with increased parameters and thus decreased computational efficiency.

Read the paper · More papers on PaperTik