CHIP and CRISP: Protecting All Parties Against Compromise Through Identity-Binding PAKEs
Cas Cremers, Moni Naor, Shahar Paz, Eyal Ronen
Abstract
Recent advances in password-based authenticated key exchange (PAKE) protocols can offer stronger security guarantees for globally deployed security protocols. Notably, the OPAQUE protocol [Euro-crypt2018] realizes Strong Asymmetric PAKE (saPAKE), strengthening the protection offered by aPAKE to compromised servers: after compromising an saPAKE server, the adversary still has to perform a full bruteforce search to recover any passwords or impersonate users. However, (s)aPAKEs do not protect client storage, and can only be applied in the so-called asymmetric setting, in which some parties, such as servers, do not communicate with each other using the protocol.
Nonetheless, passwords are also widely used in symmetric settings, where a group of parties share a password and can all communicate (e.g., Wi-Fi with client devices, routers, and mesh nodes; or industrial IoT scenarios). In these settings, the (s)aPAKE techniques cannot be applied, and the state-of-the-art still involves handling plaintext passwords.
In this work, we propose the notions of (strong) identity-binding PAKEs that improve this situation: they protect against compromise of any party, and can also be applied in the symmetric setting. We propose counterparts to state-of-the-art security notions from the asymmetric setting in the UC model, and construct protocols that provably realize them. Our constructions bind the local storage of all parties to abstract identities, building on ideas from identity-based key exchange, but without requiring a third party.
Our first protocol, CHIP, generalizes the security of aPAKE protocols to all parties, forcing the adversary to perform a brute-force search to recover passwords or impersonate others. Our second protocol, CRISP, additionally renders any adversarial pre-computation useless, thereby offering saPAKE-like guarantees for all parties, instead of only the server.
We evaluate prototype implementations of our protocols and show that even though they offer stronger security for real-world use cases, their performance is in line with, or even better than, state-of-the-art protocols.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e593f06a-8611-4113-b4d6-8b1efcc7f2b0Cited by top-tier papers1
Ask how each one uses itRelated papers
- LATKE: A Framework for Constructing Identity-Binding PAKEsJonathan Katz, Michael RosenbergCRYPTO 2024 · 5 citations
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 34 citations
- OneTwoPAKE: Two-Round Strong Asymmetric PAKE with Ideal SecurityYashvanth Kondi, Ian McQuoid, Kelsey Melissaris, Claudio Orlandi et al.EUROCRYPT 2026 · 1 citation
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki et al.CRYPTO 2020 · 42 citations
- Bare PAKE: Universally Composable Key Exchange from Just PasswordsManuel Barbosa, Kai Gellert, Julia Hesse, Stanislaw JareckiCRYPTO 2024 · 11 citations
