Password-Authenticated Public-Key Encryption

Password-Authenticated Public-Key Encryption
复制标题

DOI:
10.1007/978-3-030-21568-2_22
复制
发表时间:
2019-06
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Tatiana Bradley;J. Camenisch;Stanislaw Jarecki;Anja Lehmann;G. Neven;Jiayu Xu
Tatiana Bradley;J. Camenisch;Stanislaw Jarecki;Anja Lehmann;G. Neven;Jiayu Xu
中科院分区:
其他
文献类型:
--
作者:
Tatiana Bradley;J. Camenisch;Stanislaw Jarecki;Anja Lehmann;G. Neven;Jiayu Xu

文献摘要

相似文献

介绍了一种新的密码原语--口令认证公钥加密(Papke)。Papke支持在两个实体之间进行安全的端到端加密,而无需依赖受信任的第三方或其他带外机制进行身份验证。相反,通过使用共享密码验证公钥,同时防止离线字典攻击,从而确保了对中间人攻击的抵抗。我们的贡献有三个方面。首先,我们为Papke提供了基于属性和通用可组合(UC)的定义,所得到的原语将公钥加密(PKE)的CCA安全性与密码身份验证相结合。其次,我们证明了Papke蕴含着口令认证密钥交换(PAKE),但反向蕴涵不成立,表明Papke是一个严格强于PAKE的原语。事实上,Papke暗示了两流PAKE,如果任何一方在多个会话中重新使用其状态(例如,由于通信错误),则该PAKE保持安全,从而加强了PAKE安全的现有概念。最后,将我们的Papke-to-PAKE编译器应用到上述Papke方案中,我们展示了第一轮UC-PAKE,其效率与(未认证)Diffie-Hellman密钥交换相当。
We introduce password-authenticated public-key encryption (PAPKE), a new cryptographic primitive. PAPKE enables secure end-to-end encryption between two entities without relying on a trusted third party or other out-of-band mechanisms for authentication. Instead, resistance to man-in-the-middle attacks is ensured in a human-friendly way by authenticating the public key with a shared password, while preventing offline dictionary attacks given the authenticated public key and/or the ciphertexts produced using this key.Our contributions are three-fold. First, we provide property-based and universally composable (UC) definitions for PAPKE, with the resulting primitive combining CCA security of public-key encryption (PKE) with password authentication. Second, we show that PAPKE implies Password-Authenticated Key Exchange (PAKE), but the reverse implication does not hold, indicating that PAPKE is a strictly stronger primitive than PAKE. Indeed, PAPKE implies a two-flow PAKE which remains secure if either party re-uses its state in multiple sessions, e.g. due to communication errors, thus strengthening existing notions of PAKE security. Third, we show two highly practical UC PAPKE schemes: a generic construction built from CCA-secure and anonymous PKE and an ideal cipher, and a direct construction based on the Decisional Diffie-Hellman assumption in the random oracle model.Finally, applying our PAPKE-to-PAKE compiler to the above PAPKE schemes we exhibit the first 2-round UC PAKE’s with efficiency comparable to (unauthenticated) Diffie-Hellman Key Exchange.