Strong Asymmetric PAKE based on Trapdoor CKEM

Strong Asymmetric PAKE based on Trapdoor CKEM
复制标题

DOI:
10.1007/978-3-030-26954-8_26
复制
发表时间:
2019-08
期刊:
--
影响因子:
--
通讯作者:
Tatiana Bradley;Stanislaw Jarecki;Jiayu Xu
Tatiana Bradley;Stanislaw Jarecki;Jiayu Xu
中科院分区:
其他
文献类型:
--
作者:
Tatiana Bradley;Stanislaw Jarecki;Jiayu Xu

文献摘要

相似文献

密码验证密钥交换(PAKE)协议允许共享密码的双方以不受脱机攻击的方式建立共享密钥。非对称PAKE(APAKE)[20]将这一概念适应于常见的客户端-服务器设置,其中服务器存储密码的单向散列而不是密码本身,并且服务器危害允许攻击者仅通过(不可避免的)离线字典攻击来恢复密码。然而,大多数aPAKE协议允许攻击者重新计算散列密码的字典,从而在服务器受损时立即获知密码。最近,Jarecki,Krawczyk和Xu形式化了一个通用可组合的StrongaPAKE(SaPAKE)[23],它要求对密码散列进行盐化,以便只有在服务器泄露了盐化的散列和盐化的散列之后,才能开始字典攻击。文献[23]中所示的UC saPAKE协议称为不透明协议,它使用3个协议流,每一方3-4次指数运算,并依赖于只读存储器中的一个以上Diffie-Hellman假设。我们提出了一种基于加密+SPHF范例的替代UC saPAKE结构用于UC PAKE设计[19,26]。与不透明协议相比,我们的协议仅使用2个流,具有可比较的代价,避免了散列到一个组上,并且依赖于不同的假设,即判决Diffie-Hellman(DDH)、强Diffie-Hellman(SDH)以及Boneh-Boyen函数[9]是Salted紧单向函数(STOWF)的假设。我们形式化了STOWF的UC模型,并分析了Boneh-Boyen函数在一般组模型和ROM中作为UC STOWF的作用。我们的saPAKE协议采用了一种新的形式的条件密钥封装机制(CKEM),它是SPHF的推广,我们称之为隐式声明CKEM。SPHF的这种增强允许UC(SA)PAKE设计,其中只有客户端提交其密码,并且只有服务器执行SPHF,而在标准UC PAKE设计范例中,双方对称地使用加密+SPHF子例程。
Password-Authenticated Key Exchange (PAKE) protocols allow two parties that share a password to establish a shared key in a way that is immune to offline attacks. Asymmetric PAKE (aPAKE) [20] adapts this notion to the common client-server setting, where the server stores a one-way hash of the password instead of the password itself, and server compromise allows the adversary to recover the password only via the (inevitable) offline dictionary attack. Most aPAKE protocols, however, allow an attacker topre-compute a dictionary of hashed passwords, thus instantly learning the password on server compromise. Recently, Jarecki, Krawczyk, and Xu formalized a Universally ComposablestrongaPAKE (saPAKE) [23], which requires the password hash to be salted so that the dictionary attack can only start after the server compromise leaks the salt and the salted hash. The UC saPAKE protocol shown in [23], called OPAQUE, uses 3 protocol flows, 3–4 exponentiations per party, and relies on the One-More Diffie-Hellman assumption in ROM.We propose an alternative UC saPAKE construction based on a novel use of the encryption+SPHF paradigm for UC PAKE design [19, 26]. Compared to OPAQUE, our protocol uses only 2 flows, has comparable costs, avoids hashing onto a group, and relies on different assumptions, namely Decisional Diffie-Hellman (DDH), Strong Diffie-Hellman (SDH), and an assumption that the Boneh-Boyen function[9] is aSalted Tight One-Way Function(STOWF). We formalize a UC model for STOWF and analyze the Boneh-Boyen function as UC STOWF in the generic group model and ROM.Our saPAKE protocol employs a new form of Conditional Key Encapsulation Mechanism (CKEM), a generalization of SPHF, which we call animplicit-statementCKEM. This strengthening of SPHF allows for a UC (sa)PAKE design where only the client commits to its password, and only the server performs an SPHF, compared to the standard UC PAKE design paradigm where the encrypt+SPHF subroutine is used symmetrically by both parties.