Password-Authenticated Key Exchange Protocols: A Survey
Ding Wang, Guanling Li, Jingwei Jiang · ACM Computing Surveys · 2025
Password-authenticated key exchange (PAKE) protocols tackle the important problem of how to enable two parties, who share a low-entropy password, to establish a cryptographically strong session key for secure data communication. Although considerable research efforts have been devoted to designing hundreds of PAKE protocols, to the best of our knowledge, there have been few systematic reviews. In this work, we provide a comprehensive overview of PAKE research. We first propose a list of 13 desirable properties of PAKE protocols in terms of security and usability, enabling PAKE protocols to be systematically rated across a common spectrum. We then provide a taxonomy for PAKE protocols, and classify them into seven types according to their underlying design strategies. For each type, we investigate the inner working mechanisms of various representative protocols, and identify their pros, and cons. We further classify existing PAKE protocols from five other key perspectives (i.e., symmetry, number of participants, hardness assumptions, security goals, and round complexity) and review their development history under each classification, aiming at providing an in-depth and thorough understanding of the status quo of PAKE research. Based on 13 properties and six perspectives, we conduct a large-scale comparative evaluation of 71 representative PAKE protocols in a systematic manner. Finally, we highlight a few potential directions for the future design of PAKE protocols.