| Security proofs for an efficient password-based key exchange |
| Full text |
Pdf
(234 KB)
|
| Source
|
Conference on Computer and Communications Security
archive
Proceedings of the 10th ACM conference on Computer and communications security
table of contents
Washington D.C., USA
SESSION: Cryptographic protocols/ network security
table of contents
Pages: 241 - 250
Year of Publication: 2003
ISBN:1-58113-738-9
|
|
Authors
|
|
| Sponsor |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 6, Downloads (12 Months): 92, Citation Count: 12
|
|
|
ABSTRACT
Password-based key exchange schemes are designed to provide entities communicating over a public network, and sharing a (short) password only, with a session key (e.g, the key is used for data integrity and/or confidentiality). The focus of the present paper is on the analysis of very efficient schemes that have been proposed to the IEEE P1363 Standard working group on password-based authenticated key-exchange methods, but which actual security was an open problem. We analyze the AuthA key exchange scheme and give a complete proof of its security. Our analysis shows that the AuthA protocol and its multiple modes of operations are provably secure under the computational Diffie-Hellman intractability assumption, in both the random-oracle and the ideal-ciphers models.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
|
 |
2
|
|
| |
3
|
M. Bellare, D. Pointcheval, and P. Rogaway. Authenticated Key Exchange Secure Against Dictionary Attacks. In Eurocrypt '00, LNCS 1807, pages 139--155. Springer-Verlag, Berlin, 2000.
|
| |
4
|
M. Bellare and P. Rogaway. The AuthA Protocol for Password-Based Authenticated Key Exchange. Contributions to IEEE P1363. March 2000. Available from http://grouper.ieee.org/groups/1363/.
|
 |
5
|
|
| |
6
|
|
 |
7
|
|
| |
8
|
S. Blake-Wilson, V. Gupta, C. Hawk, and B. Moeller. ECC Cipher Suites for TLS, February 2002. IEEE RFC 20296.
|
 |
9
|
|
| |
10
|
|
| |
11
|
V. Boyko, P. MacKenzie, and S. Patel. Provably Secure Password Authenticated Key Exchange Using Diffie-Hellman. In Eurocrypt '00, LNCS 1807, pages 156--171. Springer-Verlag, Berlin, 2000.
|
| |
12
|
|
 |
13
|
|
| |
14
|
E. Bresson, O. Chevassut, and D. Pointcheval. Encrypted Key Exchange using Mask Generation Function. Work in progress.
|
| |
15
|
|
| |
16
|
|
| |
17
|
|
| |
18
|
J. Katz, R. Ostrovsky, and M. Yung. Forward Secrecy in Password-only Key Exchange Protocols. In Proc. of SCN '02, 2002.
|
 |
19
|
|
| |
20
|
D. Taylor. Using SRP for TLS Authentication, november 2002. Internet Draft.
|
| |
21
|
IEEE Standard 1363--2000. Standard Specifications for Public Key Cryptography. IEEE. Available from http://grouper.ieee.org/groups/1363, August 2000.
|
| |
22
|
IEEE Standard 1363.2 Study Group. Password-Based Public-Key Cryptography. Available from http://grouper.ieee.org/groups/1363/passwdPK.
|
| |
23
|
Wireless Application Protocol. Wireless Transport Layer Security Specification, February 2000. WAP TLS, WAP-199 WTLS.
|
CITED BY 12
|
|
|
|
|
Liang Fang , Samuel Meder , Olivier Chevassut , Frank Siebenlist, Secure password-based authenticated key exchange for web services, Proceedings of the 2004 workshop on Secure web service, p.9-15, October 29-29, 2004, Fairfax, Virginia
|
|
|
|
|
|
|
|
|
|
|
|
Michel Abdalla , Emmanuel Bresson , Olivier Chevassut , Bodo Möller , David Pointcheval, Provably secure password-based authentication in TLS, Proceedings of the 2006 ACM Symposium on Information, computer and communications security, March 21-24, 2006, Taipei, Taiwan
|
|
|
|
|
|
|
|
|
Sebastian Gajek , Mark Manulis , Ahmad-Reza Sadeghi , Jörg Schwenk, Provably secure browser-based user-aware mutual authentication over TLS, Proceedings of the 2008 ACM symposium on Information, computer and communications security, March 18-20, 2008, Tokyo, Japan
|
|
|
|
|
|
|
|
|
|
|