Passwords are commonly used for authentication, but their susceptibility to brute force and dictionary attacks poses a significant risk. To mitigate this issue, Password Authenticated Key Exchange ( \(\textsf{PAKE}\) ) was introduced, enabling two parties to establish a shared secret key using only a low-entropy password. Over the past thirty years, numerous \(\textsf{PAKE}\) protocols have emerged, focusing on enhancing security against various attacks and ensuring efficiency. Despite these advancements, many challenges remain. To address impersonation attacks, Cremers et al. introduced a new variant called identity-binding \(\textsf{PAKE}\) at Crypto ’22, enabling the user to bind their password with their identity while generating the password file in the registration phase. However, current identity-binding \(\textsf{PAKE}\) protocols are vulnerable to quantum attacks and often lack desirable security properties. In response to these challenges, our contribution aims to bridge the gap between practical and secure post-quantum identity-binding \(\textsf{PAKE}\) . Our work proposes a post-quantum secure identity-binding \(\textsf{PAKE}\) protocol, \(\textsf{CPAKE}\) , with enhanced security in a code-based setting. Code-based cryptography, being a strong candidate for post-quantum cryptography, can produce many of the key primitives needed for the quantum era. \(\textsf{CPAKE}\) is secure under the hardness of the Decisional s-Quasi-Cyclic Syndrome Decoding Problem (s- \(\textsf{DQCSDP}\) ). We present comprehensive security proof in a conventional game-based indistinguishability security model. Through rigorous performance evaluations, the paper demonstrates that the proposed \(\textsf{PAKE}\) scheme exhibits notable advantages in terms of total computation cost when compared to existing identity-binding \(\textsf{PAKE}\) protocols.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CPAKE: An Identity-Binding Password Authenticated Key Exchange from Quasi-cyclic Codes

  • Pratima Jana,
  • Ratna Dutta

摘要

Passwords are commonly used for authentication, but their susceptibility to brute force and dictionary attacks poses a significant risk. To mitigate this issue, Password Authenticated Key Exchange ( \(\textsf{PAKE}\) ) was introduced, enabling two parties to establish a shared secret key using only a low-entropy password. Over the past thirty years, numerous \(\textsf{PAKE}\) protocols have emerged, focusing on enhancing security against various attacks and ensuring efficiency. Despite these advancements, many challenges remain. To address impersonation attacks, Cremers et al. introduced a new variant called identity-binding \(\textsf{PAKE}\) at Crypto ’22, enabling the user to bind their password with their identity while generating the password file in the registration phase. However, current identity-binding \(\textsf{PAKE}\) protocols are vulnerable to quantum attacks and often lack desirable security properties. In response to these challenges, our contribution aims to bridge the gap between practical and secure post-quantum identity-binding \(\textsf{PAKE}\) . Our work proposes a post-quantum secure identity-binding \(\textsf{PAKE}\) protocol, \(\textsf{CPAKE}\) , with enhanced security in a code-based setting. Code-based cryptography, being a strong candidate for post-quantum cryptography, can produce many of the key primitives needed for the quantum era. \(\textsf{CPAKE}\) is secure under the hardness of the Decisional s-Quasi-Cyclic Syndrome Decoding Problem (s- \(\textsf{DQCSDP}\) ). We present comprehensive security proof in a conventional game-based indistinguishability security model. Through rigorous performance evaluations, the paper demonstrates that the proposed \(\textsf{PAKE}\) scheme exhibits notable advantages in terms of total computation cost when compared to existing identity-binding \(\textsf{PAKE}\) protocols.