Password-Protected Key Retrieval with(out) HSM Protection
Sebastian H. Faller, Tobias Handirk, Julia Hesse, Máté Horváth, Anja Lehmann
Abstract
Password-protected key retrieval (PPKR) enables users to store and retrieve high-entropy keys from a server securely. The process is bootstrapped from a human-memorizable password only, addressing the challenge of how end-users can manage cryptographic key material. The core security requirement is protection against a corrupt server, which should not be able to learn the key or offlineattack it through the password protection. PPKR is deployed at a large scale with the WhatsApp Backup Protocol (WBP), allowing users to access their encrypted messaging history when switching to a new device. Davies et al. (Crypto'23) formally analyzed the WBP, proving that it satisfies most of the desired security. The WBP uses the OPAQUE protocol for password-based key exchange as a building block and relies on the server using a hardware security module (HSM) for most of its protection. In fact, the security analysis assumes that the HSM is incorruptible -rendering most of the heavy cryptography in the WBP obsolete. In this work, we explore how provably secure and efficient PPKR can be built that either relies strongly on an HSM -but then takes full advantage of that -or requires less trust assumption for the price of more advanced cryptography. To this end, we expand the definitional work by Davies et al. to allow the analysis of PPKR with fine-grained HSM corruption, such as leakage of user records or attestation keys. For each scenario, we aim to give minimal PPKR solutions. For the strongest corruption setting, namely a fully corrupted HSM, we propose a protocol with a simpler design and better efficiency than the WBP. We also fix an attack related to client authentication that was identified by Davies et al. CCS Concepts • Security and privacy → Key management; Public key (asymmetric) techniques.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db4a42de-bd46-45e2-81b9-d8f9e9ad9ecdCited by top-tier papers1
Ask how each one uses itBuilds on6
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin et al.USENIX Security 2018 · 1,175 citations
- DiSE: Distributed Symmetric-key EncryptionShashank Agrawal, Payman Mohassel, Pratyay Mukherjee, Peter RindalCCS 2018 · 45 citations
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk et al.CRYPTO 2023 · 29 citations
- Trust Dies in Darkness: Shedding Light on Samsung's TrustZone Keymaster DesignAlon Shakevsky, Eyal Ronen, Avishai WoolUSENIX Security 2022
- How to Recover a Cryptographic Secret From the CloudDavid Adei, Chris Orsini, Alessandra Scafuro, Tanner VerberCCS 2025
Related papers
- Simple Password-Hardened Encryption ServicesRussell W. F. Lai, Christoph Egger, Manuel Reinert, Sherman S. M. Chow et al.USENIX Security 2018 · 33 citations
- End-to-Same-End Encryption: Modularly Augmenting an App with an Efficient, Portable, and Blind Cloud StorageLong Chen, Ya-Nan Li, Qiang Tang, Moti YungUSENIX Security 2022
- Compact Key Storage - A Modern Approach to Key Backup and DelegationYevgeniy Dodis, Daniel Jost, Antonio MarcedoneCRYPTO 2024 · 2 citations
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 34 citations
- Threshold Password-Hardened Encryption ServicesJulian Brost, Christoph Egger, Russell W. F. Lai, Fritz Schmid et al.CCS 2020 · 24 citations
