Owl: An Augmented Password-Authenticated Key Exchange Scheme

被引:0
|
作者
Hao, Feng [1 ]
Bag, Samiran [1 ]
Chen, Liqun [2 ]
van Oorschot, Paul C. [3 ]
机构
[1] Univ Warwick, Coventry, W Midlands, England
[2] Univ Surrey, Guildford, Surrey, England
[3] Carleton Univ, Ottawa, ON, Canada
基金
英国工程与自然科学研究理事会; 加拿大自然科学与工程研究理事会;
关键词
D O I
10.1007/978-3-031-78679-2_12
中图分类号
F8 [财政、金融];
学科分类号
0202 ;
摘要
We present Owl, an augmented password-authenticated key exchange (PAKE) protocol that is both efficient and supported by security proofs. Owl is motivated by recognized limitations in SRP-6a and OPAQUE. SRP-6a is the only augmented PAKE that has enjoyed wide use in practice to date, but it lacks the support of formal security proofs, and does not support elliptic curve settings. OPAQUE was proposed in 2018 as a provably secure and efficient alternative to SRP-6a, and was chosen by the IETF in 2020 for standardization, but open issues leave it unclear whether OPAQUE will replace SRP-6a in practice. Owl is obtained by efficiently adapting J-PAKE to an asymmetric setting, providing additional security against server compromise yet with lower computation than J-PAKE. Owl is provably secure, efficient and agile in supporting implementations in diverse multiplicative groups and elliptic curve settings. To the best of our knowledge, Owl is the first augmented PAKE solution that provides systematic advantages over SRP-6a in terms of security, computation, message sizes, and agility.
引用
收藏
页码:227 / 244
页数:18
相关论文
共 50 条
  • [1] Threshold password-authenticated key exchange
    MacKenzie, P
    Shrimpton, T
    Jakobsson, M
    JOURNAL OF CRYPTOLOGY, 2006, 19 (01) : 27 - 66
  • [2] Fuzzy Password-Authenticated Key Exchange
    Dupont, Pierre-Alain
    Hesse, Julia
    Pointcheval, David
    Reyzin, Leonid
    Yakoubov, Sophia
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2018, PT III, 2018, 10822 : 393 - 424
  • [3] Threshold Password-Authenticated Key Exchange
    Philip MacKenzie
    Thomas Shrimpton
    Markus Jakobsson
    Journal of Cryptology, 2006, 19 : 27 - 66
  • [4] Security Analysis of Two Augmented Password-Authenticated Key Exchange Protocols
    Shin, SeongHan
    Kobara, Kazukuni
    Imai, Hideki
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2010, E93A (11): : 2092 - 2095
  • [5] Password-authenticated key exchange based on RSA
    MacKenzie, Philip
    Patel, Sarvar
    Swaminathan, Ram
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2010, 9 (06) : 387 - 410
  • [6] More efficient password-authenticated key exchange
    MacKenzie, P
    TOPICS IN CRYPTOLOGY - CT-RAS 2001, PROCEEDINGS, 2001, 2020 : 361 - 377
  • [7] Faster and shorter password-authenticated key exchange
    Gennaro, Rosario
    THEORY OF CRYPTOGRAPHY, 2008, 4948 : 589 - 606
  • [8] Password-authenticated key exchange based on RSA
    Philip MacKenzie
    Sarvar Patel
    Ram Swaminathan
    International Journal of Information Security, 2010, 9 : 387 - 410
  • [9] Parallelizable password-authenticated key exchange protocol
    Lee, SW
    Yoo, KY
    PARALLEL PROCESSING AND APPLIED MATHEMATICS, 2004, 3019 : 1014 - 1019
  • [10] Password-authenticated key exchange based on RSA
    MacKenzie, P
    Patel, S
    Swaminathan, R
    ADVANCES IN CRYPTOLOGY ASIACRYPT 2000, PROCEEDINGS, 2000, 1976 : 599 - 613