On the UC-(In)Security of PAKE Protocols Without the Random Oracle Model
Naman Kumar, Jiayu Xu
Abstract
A Password-Authenticated Key Exchange (PAKE) protocol allows two parties to jointly establish a cryptographic key, where the only information shared in advance is a low-entropy password. The first efficient PAKE protocol whose security does not rely on the random oracle model is the one by Katz, Ostrovsky and Yung (KOY, EUROCRYPT 2001). Unfortunately, the KOY protocol has only been proven secure in the game-based setting, and it is unclear whether KOY is secure in the stronger Universal Composability (UC) framework, which is the current security standard for PAKE.
In this work, we present a thorough study of the UC-security of KOY. Our contributions are two-fold:
1. We formally prove that the KOY protocol is not UC-secure;
2. We then show that the UC-security of KOY holds in the Algebraic Group Model, under the Decisional Square Diffie-Hellman (DSDH) assumption.
Overall, we characterize the exact conditions under which KOY is UC-secure. Interestingly, the DSDH assumption is stronger than DDH under which KOY can be proven game-based secure, which reveals some subtle gaps between the two PAKE security notions that have never been studied.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get bf44027c-c8a3-4780-abff-1e1c470a3ab7Related papers
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 7 citations
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki et al.CRYPTO 2020 · 42 citations
- Universal Composable Password Authenticated Key Exchange for the Post-Quantum WorldYou Lyu, Shengli Liu, Shuai HanEUROCRYPT 2024 · 11 citations
- Just How Secure is SRP, Really?Jiayu Xu, Zhiyuan ZhaoCRYPTO 2026
- PAKE Combiners and Efficient Post-quantum InstantiationsJulia Hesse, Michael RosenbergEUROCRYPT 2025 · 7 citations
