On the UC-(In)Security of PAKE Protocols Without the Random Oracle Model
Naman Kumar, Jiayu Xu
摘要
A Password-Authenticated Key Exchange (PAKE) protocol allows two parties to jointly establish a cryptographic key, where the only information shared in advance is a low-entropy password. The first efficient PAKE protocol whose security does not rely on the random oracle model is the one by Katz, Ostrovsky and Yung (KOY, EUROCRYPT 2001). Unfortunately, the KOY protocol has only been proven secure in the game-based setting, and it is unclear whether KOY is secure in the stronger Universal Composability (UC) framework, which is the current security standard for PAKE.
In this work, we present a thorough study of the UC-security of KOY. Our contributions are two-fold:
1. We formally prove that the KOY protocol is not UC-secure;
2. We then show that the UC-security of KOY holds in the Algebraic Group Model, under the Decisional Square Diffie-Hellman (DSDH) assumption.
Overall, we characterize the exact conditions under which KOY is UC-secure. Interestingly, the DSDH assumption is stronger than DDH under which KOY can be proven game-based secure, which reveals some subtle gaps between the two PAKE security notions that have never been studied.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Under What Conditions Is Encrypted Key Exchange Actually Secure?Jake Januzelli, Lawrence Roy, Jiayu XuEUROCRYPT 2025 · 被引用 7 次
- Universally Composable Relaxed Password Authenticated Key ExchangeMichel Abdalla, Manuel Barbosa, Tatiana Bradley, Stanislaw Jarecki 等CRYPTO 2020 · 被引用 42 次
- Universal Composable Password Authenticated Key Exchange for the Post-Quantum WorldYou Lyu, Shengli Liu, Shuai HanEUROCRYPT 2024 · 被引用 11 次
- Just How Secure is SRP, Really?Jiayu Xu, Zhiyuan ZhaoCRYPTO 2026
- PAKE Combiners and Efficient Post-quantum InstantiationsJulia Hesse, Michael RosenbergEUROCRYPT 2025 · 被引用 7 次
