Updatable aPAKE: Security Against Bulk Precomputation Attacks
Dennis Dayanikli, Anja Lehmann
摘要
Asymmetric Password-Authenticated Key Exchange (aPAKE) enables secure key establishment between a client and a server using a pre-shared password, while providing security against offline attacks. However, aPAKE does not guarantee any precomputation resistance, and considers passwords to become immediately available upon server compromise. A recent work by Dayanikli and Lehmann (EuroS&P'24) observed that many existing aPAKE protocols provide stronger precomputation attack resistance than what is guaranteed through the aPAKE model: they often rely on salted password hashes, where a unique salt makes precomputation attacks more difficult. While these salts are sent in clear to the client during authentication, and thus trivial to obtain for an attacker, this makes a difference in multi-user settings with millions of user accounts per server. In order to run bulk precomputation attacks on all users' passwords, the attacker needs to start an authentication session on behalf of every user to obtain their salts. However, this protection is still limited as salts are static, and the attacker can gradually extract all salt values for precomputation attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Poseidon: A New Hash Function for Zero-Knowledge Proof SystemsLorenzo Grassi, Dmitry Khovratovich, Christian Rechberger, Arnab Roy 等USENIX Security 2021 · 被引用 410 次
- KHAPE: Asymmetric PAKE from Key-Hiding Key ExchangeYanqi Gu, Stanislaw Jarecki, Hugo KrawczykCRYPTO 2021 · 被引用 34 次
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk 等CRYPTO 2023 · 被引用 29 次
- Crypto Dark Matter on the Torus - Oblivious PRFs from Shallow PRFs and TFHEMartin R. Albrecht, Alex Davidson, Amit Deo, Daniel GardhamEUROCRYPT 2024 · 被引用 27 次
- Asymmetric PAKE with Low Computation and communicationBruno Freitas Dos Santos, Yanqi Gu, Stanislaw Jarecki, Hugo KrawczykEUROCRYPT 2022 · 被引用 22 次
相关 Paper
- Just How Secure is SRP, Really?Jiayu Xu, Zhiyuan ZhaoCRYPTO 2026
- OneTwoPAKE: Two-Round Strong Asymmetric PAKE with Ideal SecurityYashvanth Kondi, Ian McQuoid, Kelsey Melissaris, Claudio Orlandi 等EUROCRYPT 2026 · 被引用 1 次
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki 等CRYPTO 2020 · 被引用 42 次
- CHIP and CRISP: Protecting All Parties Against Compromise Through Identity-Binding PAKEsCas Cremers, Moni Naor, Shahar Paz, Eyal RonenCRYPTO 2022 · 被引用 13 次
- Practical Anonymous Password Authentication and TLS with Anonymous Client AuthenticationZhenfeng Zhang, Kang Yang, Xuexian Hu, Yuchen WangCCS 2016 · 被引用 36 次
