Password Authenticated Key Exchange

Stanisław Jarecki · 2022

Protocols for password authenticated key exchange (PAKE) allow two parties who share only a low-entropy password to agree on a cryptographically strong key by communicating over an insecure network. This chapter overviews cryptographic literature on PAKE, and it discusses in depth PAKE security models, and in that aspect it is more a tutorial and reassessment than a survey. It presents a survey on two important variants of the PAKE problem: the client-server, also known as asymmetric PAKE, and multi-server, a.k.a. threshold PAKE. The chapter reviews the game-based PAKE security model and the simulation-based PAKE security model. The Boyko-MacKenzie-Patel model for PAKE security appeared in the same year as the Bellare-Pointcheval-Rogaway model. Post-termination password tests were reintroduced to the UC framework as a lazy-extraction UC PAKE.

Read the paper · More papers on PaperTik