Bare PAKE: Universally Composable Key Exchange from Just Passwords
Manuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw Jarecki
Abstract
In the past three decades, an impressive body of knowledge has been built around secure and private password authentication. In particular, secure password-authenticated key exchange (PAKE) protocols require only minimal overhead over a classical Diffie-Hellman key exchange. PAKEs are also known to fulfill strong composable security guarantees that capture many password-specific concerns such as password correlations or password mistyping, to name only a few. However, to enjoy both round-optimality and strong security, applications of PAKE protocols must provide unique session and participant identifiers. If such identifiers are not readily available, they must be agreed upon at the cost of additional communication flows, a fact which has been met with incomprehension among practitioners, and which hindered the adoption of provably secure password authentication in practice.
In this work, we resolve this issue by proposing a new paradigm for truly password-only yet securely composable PAKE, called bare PAKE. We formally prove that two prominent PAKE protocols, namely CPace and EKE, can be cast as bare PAKEs and hence do not require pre-agreement of anything else than a password. Our bare PAKE modeling further allows us to investigate a novel "reusability" property of PAKEs, i.e., whether pairwise keys can be exchanged from only messages, just as the Diffie-Hellman non-interactive key exchange can do in a public-key setting. As a side contribution, this add-on property of bare PAKEs leads us to observe that some previous PAKE constructions relied on unnecessarily strong, "reusable" building blocks. By showing that ``non-reusable'' tools suffice for standard PAKE, we open a new path towards round-optimal post-quantum secure password-authenticated key exchange.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Rethinking Access Control and Authentication for the Home Internet of Things (IoT)Weijia He, Maximilian Golla, Roshni Padhi, Jordan Ofek et al.USENIX Security 2018 · 221 citations
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki et al.CRYPTO 2020 · 42 citations
- Provable Security Analysis of FIDO2Manuel Barbosa, Alexandra Boldyreva, Shan Chen, Bogdan WarinschiCRYPTO 2021 · 42 citations
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 34 citations
- Asymmetric PAKE with Low Computation and communicationBruno Freitas Dos Santos, Yanqi Gu, Stanislaw Jarecki, Hugo KrawczykEUROCRYPT 2022 · 22 citations
Related papers
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 7 citations
- LATKE: A Framework for Constructing Identity-Binding PAKEsJonathan Katz, Michael RosenbergCRYPTO 2024 · 5 citations
- PAKE Combiners and Efficient Post-quantum InstantiationsJulia Hesse, Michael RosenbergEUROCRYPT 2025 · 7 citations
- CHIP and CRISP: Protecting All Parties Against Compromise Through Identity-Binding PAKEsCas Cremers, Moni Naor, Shahar Paz, Eyal RonenCRYPTO 2022 · 13 citations
- Hybrid Password Authentication Key Exchange in the UC FrameworkYou Lyu, Shengli LiuEUROCRYPT 2025 · 8 citations
