Paper published in a book (Scientific congresses, symposiums and conference proceedings)
On Password-Authenticated Key Exchange Security Modeling
Lancrenon, Jean
2016In Stajano, Frank; Mjolsnes, Stig; Jenkinson, Graeme et al. (Eds.) Technology and practice of passwords: 9th International Conference, PASSWORDS 2015, Cambridge, UK, December 7-9, 2015, Proceedings
Peer reviewed
 

Files


Full Text
PaperV3.pdf
Author postprint (461.79 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Password-authenticated key exchange; Security models; Provable security
Abstract :
[en] Deciding which security model is the right one for Authenticated Key Exchange (AKE) is well-known to be a difficult problem. In this paper, we examine definitions of security for Password-AKE (PAKE) in the style proposed by Bellare et al. at Eurocrypt 2000. Indeed, there does not seem to be any consensus, even when narrowing the study down to this particular authentication method and model style, on how to precisely define fundamental notions such as accepting, terminating, and partnering. The aim of this paper is to begin addressing this problem. We first show how definitions vary from paper to paper. We then propose and thoroughly motivate a definition of our own, and use the opportunity to correct a minor flaw in a more recent and more PAKE-appropriate model proposed by Abdalla et al. at Public Key Cryptography 2005. Finally, we argue that the uniqueness of partners holding with overwhelming probability ought to be an explicitly required and proven property for AKE in general, but even more so in the password case, where the optimal security bound one aims to achieve is no longer a negligible value. To drive this last point, we exhibit a protocol that is provably secure following the Abdalla et al. definition, and at the same time fails to satisfy this property.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust
Disciplines :
Computer science
Author, co-author :
Lancrenon, Jean ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
External co-authors :
no
Language :
English
Title :
On Password-Authenticated Key Exchange Security Modeling
Publication date :
March 2016
Event name :
Passwords 2015
Event organizer :
University of Cambridge
Event place :
Cambridge, United Kingdom
Event date :
from 07-12-2015 to 09-12-2015
Audience :
International
Main work title :
Technology and practice of passwords: 9th International Conference, PASSWORDS 2015, Cambridge, UK, December 7-9, 2015, Proceedings
Editor :
Stajano, Frank
Mjolsnes, Stig
Jenkinson, Graeme
Thorsheim, Per
Publisher :
Springer
ISBN/EAN :
978-3-319-29937-2
Collection name :
LNCS 9551
Peer reviewed :
Peer reviewed
Focus Area :
Computational Sciences
FnR Project :
FNR8293135 - A Theory Of Matching Sessions, 2014 (01/05/2015-30/04/2018) - Peter Y. A. Ryan
Funders :
FNR - Fonds National de la Recherche [LU]
Available on ORBilu :
since 15 March 2016

Statistics


Number of views
114 (24 by Unilu)
Number of downloads
245 (5 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0

Bibliography


Similar publications



Contact ORBilu