Under What Conditions Is Encrypted Key Exchange Actually Secure?
Jake Januzelli, Lawrence Roy, Jiayu Xu
Abstract
A Password-Authenticated Key Exchange (PAKE) protocol allows two parties to agree upon a cryptographic key, in the setting where the only secret shared in advance is a low-entropy password. The standard security notion for PAKE is in the Universal Composability (UC) framework. In recent years there have been a large number of works analyzing the UC-security of Encrypted Key Exchange (EKE), the very first PAKE protocol, and its One-encryption variant (OEKE), both of which compile an unauthenticated Key Agreement (KA) protocol into a PAKE. In this work, we present a comprehensive and thorough study of the UC-security of both EKE and OEKE in the most general setting and using the most efficient building blocks:
- We show that among the five existing results on the UC-security of (O)EKE using a general KA protocol, all are incorrect;
- We show that for (O)EKE to be UC-secure, the underlying KA protocol needs to satisfy several additional security properties: though some of these are closely related to existing security properties, some are new, and all are missing from existing works on (O)EKE;
- We give UC-security proofs for EKE and OEKE using Programmable-Once Public Function (POPF), which is the most efficient instantiation to date and is around 4 times faster than the standard instantiation using Ideal Cipher (IC). Our results in particular allow for PAKE constructions from post-quantum KA protocols such as Kyber. We also present a security analysis of POPF using a new, weakened notion of almost UC realizing a functionality, that is still sufficient for proving composed protocols to be fully UC-secure.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Minimal Symmetric PAKE and 1-out-of-N OT from Programmable-Once Public FunctionsIan McQuoid, Mike Rosulek, Lawrence RoyCCS 2020
- On the UC-(In)Security of PAKE Protocols Without the Random Oracle ModelNaman Kumar, Jiayu XuCRYPTO 2026
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki et al.CRYPTO 2020 · 42 citations
- Universal Composable Password Authenticated Key Exchange for the Post-Quantum WorldYou Lyu, Shengli Liu, Shuai HanEUROCRYPT 2024 · 11 citations
- Bare PAKE: Universally Composable Key Exchange from Just PasswordsManuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw JareckiCRYPTO 2024 · 11 citations
