Related Experiment Videos
Password-only authenticated three-party key exchange with provable security in the standard model
Junghyun Nam1, Kim-Kwang Raymond Choo2, Junghwan Kim1
1Department of Computer Engineering, Konkuk University, 268 Chungwondaero, Chungju, Chungcheongbukdo 380-701, Republic of Korea.
This study introduces the first three-party password-only authenticated key exchange (PAKE) protocol with security proven without idealized assumptions, addressing insider attacks. The new protocol offers enhanced security against dictionary attacks for password-based key exchange.
Area of Science:
- Computer Science
- Cryptography
- Network Security
Background:
- Three-party password-only authenticated key exchange (PAKE) protocols enable two clients to establish a shared secret key via a server.
- Existing PAKE protocols often rely on idealized assumptions like random oracles or do not account for insider threats, potentially compromising security.
- Vulnerabilities arise when random oracles are implemented with specific hash functions or when insider attacks target partner clients.
Purpose of the Study:
- To present the first three-party PAKE protocol with security rigorously proven without idealized assumptions.
- To develop a protocol secure within a model that explicitly considers insider attacks.
- To ensure robust password security against undetectable online dictionary attacks.
Main Methods:
- Developed a novel three-party PAKE protocol.
- Employed a variant of the indistinguishability-based security model by Bellare, Pointcheval, and Rogaway (2000) for security proofs.
- The security analysis was conducted in a model that captures insider attacks, avoiding reliance on random oracles.
Main Results:
- The proposed protocol achieves provable security without idealized assumptions.
- Security is demonstrated within a model that incorporates insider attacks.
- The protocol provides indistinguishability-based security for session keys and robust password security against online dictionary attacks.
Conclusions:
- This work presents a significant advancement in three-party PAKE protocol security by eliminating idealized assumptions.
- The protocol offers enhanced protection against insider threats and sophisticated dictionary attacks.
- It establishes a new benchmark for secure password-based key exchange in practical, real-world scenarios.
Related Concept Videos
Norton's Theorem
Strategies of Self-Presentation II: Self-Verification
Free Energy Changes for Nonstandard States
Second Uniqueness Theorem
In contrast, consider that the electric field is non-unique and apply Gauss's law in divergence form in the region between the conductors and the integral form to the surface...
Net Change Theorem
Protecting Groups for Aldehydes and Ketones: Introduction