Universally Composable Relaxed Password Authenticated Key Exchange
Michel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki, Jonathan Katz, Jiayu Xu
Abstract
Protocols for password authenticated key exchange (PAKE) allow two parties who share only a weak password to agree on a cryptographically strong key. We revisit the notion of PAKE in the framework of universal composability, and propose a relaxation of the PAKE functionality of Canetti et al. that we call lazy-extraction PAKE (lePAKE). Roughly, our relaxation allows the ideal-world adversary to postpone its password guess even until after a session is complete. We argue that this relaxed notion still provides meaningful security in the password-only setting.
As our main result, we show that several PAKE protocols that were previously only proven secure with respect to a "game-based" definition can in fact be shown to realize the lePAKE functionality in the random-oracle model. These include SPEKE, SPAKE2, and TBPEKE, the most efficient PAKE schemes currently known.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 34 citations
- Bare PAKE: Universally Composable Key Exchange from Just PasswordsManuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw JareckiCRYPTO 2024 · 11 citations
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 2 citations
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
- Minimal Symmetric PAKE and 1-out-of-N OT from Programmable-Once Public FunctionsIan McQuoid, Mike Rosulek, Lawrence RoyCCS 2020
Related papers
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 7 citations
- On the UC-(In)Security of PAKE Protocols Without the Random Oracle ModelNaman Kumar, Jiayu XuCRYPTO 2026
- OneTwoPAKE: Two-Round Strong Asymmetric PAKE with Ideal SecurityYashvanth Kondi, Ian McQuoid, Kelsey Melissaris, Claudio Orlandi et al.EUROCRYPT 2026 · 1 citation
- How to Tolerate Typos in Strong Asymmetric PAKEIan McQuoid, Mike Rosulek, Jiayu XuCRYPTO 2025 · 3 citations
- Hybrid Password Authentication Key Exchange in the UC FrameworkYou Lyu, Shengli LiuEUROCRYPT 2025 · 8 citations
