Password-Authenticated Key Exchange from Group Actions

被引:17
|
作者
Abdalla, Michel [1 ,2 ]
Eisenhofer, Thorsten [3 ]
Kiltz, Eike [3 ]
Kunzweiler, Sabrina [3 ]
Riepel, Doreen [3 ]
机构
[1] DFINITY, Zurich, Switzerland
[2] PSL Univ, CNRS, DIENS, Ecole Normale Super, Paris, France
[3] Ruhr Univ Bochum, Bochum, Germany
来源
关键词
Password-authenticated key exchange; group actions; CSIDH; FRAMEWORK; SECURE;
D O I
10.1007/978-3-031-15979-4_24
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We present two provably secure password-authenticated key exchange (PAKE) protocols based on a commutative group action. To date the most important instantiation of isogeny-based group actions is given by CSIDH. To model the properties more accurately, we extend the framework of cryptographic group actions (Alamati et al., ASIACRYPT 2020) by the ability of computing the quadratic twist of an elliptic curve. This property is always present in the CSIDH setting and turns out to be crucial in the security analysis of our PAKE protocols. Despite the resemblance, the translation of Diffie-Hellman based PAKE protocols to group actions either does not work with known techniques or is insecure ("How not to create an isogeny-based PAKE", Azarderakhsh et al., ACNS 2020). We overcome the difficulties mentioned in previous work by using a "bit-by-bit" approach, where each password bit is considered separately. Our first protocol X-GA-PAKE(l) can be executed in a single round. Both parties need to send two set elements for each password bit in order to prevent offline dictionary attacks. The second protocol Com-GA-PAKE(l) requires only one set element per password bit, but one party has to send a commitment on its message first. We also discuss different optimizations that can be used to reduce the computational cost. We provide comprehensive security proofs for our base protocols and deduce security for the optimized versions.
引用
收藏
页码:699 / 728
页数:30
相关论文
共 50 条
  • [41] A secure and efficient password-authenticated group key exchange protocol for mobile ad hoc networks
    He, Daojing
    Chen, Chun
    Ma, Maode
    Chan, Sammy
    Bu, Jiajun
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2013, 26 (04) : 495 - 504
  • [42] Improved client-to-client password-authenticated key exchange protocol
    Gang, Yao
    Dengguo, Feng
    Xiaoxi, Han
    ARES 2007: SECOND INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2007, : 564 - +
  • [43] Anonymous Password-Authenticated Key Exchange: New Construction and Its Extensions
    Shin, SeongHan
    Kobara, Kazukuni
    Imai, Hideki
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2010, E93A (01) : 102 - 115
  • [44] The relationship between password-authenticated key exchange and other cryptographic primitives
    Nguyen, MH
    THEORY OF CRYPTOGRAPHY, PROCEEDINGS, 2005, 3378 : 457 - 475
  • [45] Provably secure three-party password-authenticated key exchange
    Lin, CL
    Wen, HA
    Hwang, T
    Sun, HM
    IEICE TRANSACTIONS ON FUNDAMENTALS OF ELECTRONICS COMMUNICATIONS AND COMPUTER SCIENCES, 2004, E87A (11) : 2990 - 3000
  • [46] nPAKE+:: A hierarchical group password-authenticated key exchange protocol using different passwords
    Wan, Zhiguo
    Deng, Robert H.
    Bao, Feng
    Preneel, Bart
    INFORMATION AND COMMUNICATIONS SECURITY, PROCEEDINGS, 2007, 4681 : 31 - +
  • [47] Continuous after-the-fact leakage-resilient group password-authenticated key exchange
    Ruan, Ou
    Wang, Zihao
    Wang, Qingping
    Zhang, Mingwu
    International Journal of Network Security, 2019, 21 (05) : 861 - 871
  • [48] Provably Secure Password-Authenticated Group Key Exchange with Different Passwords under Standard Assumption
    Wang, Fengjiao
    Zhang, Yuqing
    INFORMATION SECURITY AND CRYPTOLOGY, 2010, 6151 : 124 - 133
  • [49] Smart Grid Multilayer Consensus Password-Authenticated Key Exchange Protocol
    Nicanfar, Hasen
    Leung, Victor C. M.
    2012 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2012,
  • [50] Provably secure threshold password-authenticated key exchange extended abstract
    Di Raimondo, M
    Gennaro, R
    ADVANCES IN CRYPTOLOGY-EUROCRYPT 2003, 2003, 2656 : 507 - 523