Persistent Asymmetric Password-Based Key Exchange
Shaoquan Jiang

TL;DR
This paper introduces a new secure and efficient asymmetric password-based key exchange protocol that resists a novel threat where a server's high entropic secret is compromised, preventing rapid password cracking.
Contribution
The paper formalizes a new threat model for asymmetric password key exchange and proposes a protocol that is both secure and resistant to this threat, with a novel analysis technique.
Findings
Protocol is proven secure under the formal model.
The protocol effectively prevents rapid password compromise after server secret breach.
Introduces a new probabilistic analysis technique for security proofs.
Abstract
Asymmetric password based key exchange is a key exchange protocol where a client and a server share a low entropic password while the server additionally owns a high entropic secret for a public key. There are simple solutions for this (e.g. Halevi and Krawczyk (ACM TISSEC 1999) and its improvement by Boyarsky (CCS 1999)). In this paper, we consider a new threat to this type of protocol: if a server's high entropic secret gets compromised (e.g., due to cryptanalysis, virus attack or a poor management), the adversary might {\em quickly} break lots of passwords and cause uncountable damage. In this case, one should not expect the protocol to be secure against an off-line dictionary attack since, otherwise, the protocol is in fact a secure password-only key exchange where the server also only has a password (by making the server high entropic secret public). Of course a password-only key…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · User Authentication and Security Systems · Cryptography and Data Security
