ACM Home Page
Please provide us with feedback. Feedback
Security proofs for an efficient password-based key exchange
Full text PdfPdf (234 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the 10th ACM conference on Computer and communications security table of contents
Washington D.C., USA
SESSION: Cryptographic protocols/ network security table of contents
Pages: 241 - 250  
Year of Publication: 2003
ISBN:1-58113-738-9
Authors
Emmanuel Bresson  CELAR, Bruz Cedex, France
Olivier Chevassut  Ernest Orlando Lawrence Berkeley National Laboratory, Berkeley, CA
David Pointcheval  CNRS--Ecole normale superieure, Paris Cedex, France
Sponsor
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 6,   Downloads (12 Months): 92,   Citation Count: 12
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/948109.948142
What is a DOI?

ABSTRACT

Password-based key exchange schemes are designed to provide entities communicating over a public network, and sharing a (short) password only, with a session key (e.g, the key is used for data integrity and/or confidentiality). The focus of the present paper is on the analysis of very efficient schemes that have been proposed to the IEEE P1363 Standard working group on password-based authenticated key-exchange methods, but which actual security was an open problem. We analyze the AuthA key exchange scheme and give a complete proof of its security. Our analysis shows that the AuthA protocol and its multiple modes of operations are provably secure under the computational Diffie-Hellman intractability assumption, in both the random-oracle and the ideal-ciphers models.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
2
 
3
M. Bellare, D. Pointcheval, and P. Rogaway. Authenticated Key Exchange Secure Against Dictionary Attacks. In Eurocrypt '00, LNCS 1807, pages 139--155. Springer-Verlag, Berlin, 2000.
 
4
M. Bellare and P. Rogaway. The AuthA Protocol for Password-Based Authenticated Key Exchange. Contributions to IEEE P1363. March 2000. Available from http://grouper.ieee.org/groups/1363/.
5
 
6
7
 
8
S. Blake-Wilson, V. Gupta, C. Hawk, and B. Moeller. ECC Cipher Suites for TLS, February 2002. IEEE RFC 20296.
9
 
10
 
11
V. Boyko, P. MacKenzie, and S. Patel. Provably Secure Password Authenticated Key Exchange Using Diffie-Hellman. In Eurocrypt '00, LNCS 1807, pages 156--171. Springer-Verlag, Berlin, 2000.
 
12
13
 
14
E. Bresson, O. Chevassut, and D. Pointcheval. Encrypted Key Exchange using Mask Generation Function. Work in progress.
 
15
 
16
 
17
 
18
J. Katz, R. Ostrovsky, and M. Yung. Forward Secrecy in Password-only Key Exchange Protocols. In Proc. of SCN '02, 2002.
19
 
20
D. Taylor. Using SRP for TLS Authentication, november 2002. Internet Draft.
 
21
IEEE Standard 1363--2000. Standard Specifications for Public Key Cryptography. IEEE. Available from http://grouper.ieee.org/groups/1363, August 2000.
 
22
IEEE Standard 1363.2 Study Group. Password-Based Public-Key Cryptography. Available from http://grouper.ieee.org/groups/1363/passwdPK.
 
23
Wireless Application Protocol. Wireless Transport Layer Security Specification, February 2000. WAP TLS, WAP-199 WTLS.

CITED BY  12

Collaborative Colleagues:
Emmanuel Bresson: colleagues
Olivier Chevassut: colleagues
David Pointcheval: colleagues