KHAPE: Asymmetric PAKE from Key-Hiding Key Exchange
Yanqi Gu, Stanislaw Jarecki, Hugo Krawczyk
Abstract
OPAQUE [Jarecki et al., Eurocrypt 2018] is an asymmetric password authenticated key exchange (aPAKE) protocol that is being developed as an Internet standard and for use within TLS 1.3. OPAQUE combines an Oblivious PRF (OPRF) with an authenticated key exchange to provide strong security properties, including security against pre-computation attacks (called saPAKE security). However, the security of OPAQUE relies crucially on the security of the OPRF. If the latter breaks (by cryptanalysis, quantum attacks or security compromise), the user's password is exposed to an offline dictionary attack. To address this weakness, we present KHAPE, a variant of OPAQUE that does not require the use of an OPRF to achieve aPAKE security, resulting in improved resilience and near-optimal computational performance. An OPRF can be optionally added to KHAPE, for enhanced saPAKE security, but without opening the password to an offline dictionary attack upon OPRF compromise. In addition to resilience to OPRF compromise, a DH-based implementation of KHAPE (using HMQV) offers the best performance among aPAKE protocols in terms of exponentiations with less than the cost of an exponentiation on top of an UNauthenticated Diffie-Hellman exchange. KHAPE uses three messages if the server initiates the exchange or four when the client does (one more than OPAQUE in the latter case). All results in the paper are proven within the UC framework in the ideal cipher model. Of independent interest is our treatment of key-hiding AKE which KHAPE uses as a main component as well as our UC proofs of AKE security for protocols 3DH (a basis of Signal), HMQV and SKEME, that we use as efficient instantiations of KHAPE.
-PK is the list of all public keys created via Init, initially empty -PK P is the list of all public keys created by P, initially empty for all P -CPK is the list of all compromised keys in PK , initially empty Keys: Initialization and Attacks
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 86d7a59e-affe-4911-8751-e11b669e943eCited by top-tier papers4
- Bare PAKE: Universally Composable Key Exchange from Just PasswordsManuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw JareckiCRYPTO 2024 · 11 citations
- PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery NetworksShihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu et al.NSDI 2025 · 2 citations
- Obfuscated Key ExchangeFelix Günther, Douglas Stebila, Shannon VeitchCCS 2024 · 1 citation
- Updatable aPAKE: Security Against Bulk Precomputation AttacksDennis Dayanikli, Anja LehmannCCS 2025
Builds on2
Related papers
- Password-Authenticated TLS via OPAQUE and Post-Handshake AuthenticationJulia Hesse, Stanislaw Jarecki, Hugo Krawczyk, Christopher A. WoodEUROCRYPT 2023 · 9 citations
- OneTwoPAKE: Two-Round Strong Asymmetric PAKE with Ideal SecurityYashvanth Kondi, Ian McQuoid, Kelsey Melissaris, Claudio Orlandi et al.EUROCRYPT 2026 · 1 citation
- CHIP and CRISP: Protecting All Parties Against Compromise Through Identity-Binding PAKEsCas Cremers, Moni Naor, Shahar Paz, Eyal RonenCRYPTO 2022 · 13 citations
- Just How Secure is SRP, Really?Jiayu Xu, Zhiyuan ZhaoCRYPTO 2026
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 7 citations
