Heterogeneous-PAKE: Bridging the Gap between PAKE Protocols and Their Real-World Deployment
Rong Wei, Fangyu Zheng, Lili Gao, Jiankuo Dong, Fan Guang, Lipeng Wan, Jingqiang Lin, Yuewu Wang · Annual Computer Security Applications Conference · 2021
Two entities, who only share a password and communicate over an insecure channel, authenticate each other and agree on a large session key for protecting their subsequent communication. This is called the password-authenticated key exchange (PAKE) protocol. PAKE protocol has been considered a suitable substitute for the prevailing hash-based authentication which is vulnerable to various attacks. However, vendors are discouraged by both its prohibitively computational overheads as well as integrating costs, leading to its limited use since being proposed.