SAE+: One-Round Provably Secure Asymmetric SAE Protocol for Client-Server Model

计算机科学 协议(科学) 计算机网络 服务器 操作系统 计算机安全 分布式计算 医学 替代医学 病理
作者
Mingping Qi,Wei Hu,Yu Tai
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 3906-3913
标识
DOI:10.1109/tifs.2024.3372799
摘要

SAE, short for Simultaneous Authentication of Equals, is a password-authenticated key exchange (PAKE) protocol, by which the two involved parties can achieve mutual authentication and derive high-entropy keys via a memorable password. Currently, the SAE protocol has been standardized and integrated into the latest WPA3 (Wi-Fi Protected Access 3) specifications for protecting Wi-Fi network access. Whereas, SAE is a symmetric PAKE protocol unable to resist the server compromise attacks, and it involves explicit key confirmation flows which may be redundant for usage in existing protocols such as the TLS 1.3, etc. So, we naturally wonder that if we can construct a provably secure one-round asymmetric PAKE from the distinguished SAE. This paper affirms this by presenting an efficient asymmetric variant of SAE, called SAE+, and backing it up with a formal security proof under the widely accepted BPR security model. The new SAE+ is designed to enable a single round-trip execution, with the client initiating the communication, making it an ideal fit for integration into IETF protocols such as TLS 1.3. This feature aligns with the requirements set forth in the "Usage of PAKE with TLS 1.3" document. The SAE+ is secure against the off-line dictionary and server compromise attacks, and supports the desired forward secrecy, i.e., compromising the long-term secret password does not compromise the secrecy of the previously established session keys. In addition, the performance evaluation results presented in this paper demonstrate that the new SAE+ has comparable computational efficiency with some existing outstanding PAKE protocols while outperforms many of them in terms of communication flows.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
shenglll完成签到 ,获得积分10
1秒前
HOHAHA发布了新的文献求助10
2秒前
算了飞完成签到,获得积分10
6秒前
6秒前
共享精神应助笑笑采纳,获得10
6秒前
kermitds完成签到 ,获得积分10
7秒前
7秒前
8秒前
10秒前
沉静白云发布了新的文献求助10
11秒前
临界给TrinhTran2001的求助进行了留言
13秒前
温暖书文发布了新的文献求助30
14秒前
ColinWine发布了新的文献求助10
16秒前
22秒前
ty心明亮完成签到 ,获得积分10
26秒前
笑笑发布了新的文献求助10
27秒前
Rye227应助酸奶烤着吃采纳,获得10
28秒前
跳跃的惮完成签到,获得积分10
29秒前
29秒前
32秒前
执着怜珊完成签到 ,获得积分10
35秒前
难过的曼柔关注了科研通微信公众号
35秒前
36秒前
我是老大应助Kora采纳,获得200
36秒前
666完成签到,获得积分20
39秒前
42秒前
桐桐应助科研通管家采纳,获得10
42秒前
科研通AI2S应助科研通管家采纳,获得10
42秒前
英姑应助科研通管家采纳,获得10
43秒前
丘比特应助科研通管家采纳,获得10
43秒前
pluto应助科研通管家采纳,获得20
43秒前
43秒前
我是老大应助小高同学采纳,获得10
47秒前
SciGPT应助虚拟的惜筠采纳,获得10
48秒前
48秒前
49秒前
欧阳娜娜完成签到,获得积分10
50秒前
51秒前
52秒前
所所应助zj采纳,获得10
52秒前
高分求助中
【此为提示信息,请勿应助】请按要求发布求助,避免被关 20000
Continuum Thermodynamics and Material Modelling 2000
Encyclopedia of Geology (2nd Edition) 2000
105th Edition CRC Handbook of Chemistry and Physics 1600
Maneuvering of a Damaged Navy Combatant 650
Периодизация спортивной тренировки. Общая теория и её практическое применение 310
Mixing the elements of mass customisation 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3778573
求助须知:如何正确求助?哪些是违规求助? 3324177
关于积分的说明 10217311
捐赠科研通 3039383
什么是DOI,文献DOI怎么找? 1668032
邀请新用户注册赠送积分活动 798482
科研通“疑难数据库(出版商)”最低求助积分说明 758385