SAE+: One-Round Provably Secure Asymmetric SAE Protocol for Client-Server Model

计算机科学 协议(科学) 计算机网络 服务器 操作系统 计算机安全 分布式计算 医学 病理 替代医学
作者
Mingping Qi,Wei Hu,Yu Tai
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 3906-3913
标识
DOI:10.1109/tifs.2024.3372799
摘要

SAE, short for Simultaneous Authentication of Equals, is a password-authenticated key exchange (PAKE) protocol, by which the two involved parties can achieve mutual authentication and derive high-entropy keys via a memorable password. Currently, the SAE protocol has been standardized and integrated into the latest WPA3 (Wi-Fi Protected Access 3) specifications for protecting Wi-Fi network access. Whereas, SAE is a symmetric PAKE protocol unable to resist the server compromise attacks, and it involves explicit key confirmation flows which may be redundant for usage in existing protocols such as the TLS 1.3, etc. So, we naturally wonder that if we can construct a provably secure one-round asymmetric PAKE from the distinguished SAE. This paper affirms this by presenting an efficient asymmetric variant of SAE, called SAE+, and backing it up with a formal security proof under the widely accepted BPR security model. The new SAE+ is designed to enable a single round-trip execution, with the client initiating the communication, making it an ideal fit for integration into IETF protocols such as TLS 1.3. This feature aligns with the requirements set forth in the "Usage of PAKE with TLS 1.3" document. The SAE+ is secure against the off-line dictionary and server compromise attacks, and supports the desired forward secrecy, i.e., compromising the long-term secret password does not compromise the secrecy of the previously established session keys. In addition, the performance evaluation results presented in this paper demonstrate that the new SAE+ has comparable computational efficiency with some existing outstanding PAKE protocols while outperforms many of them in terms of communication flows.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
草莓不梅完成签到 ,获得积分10
1秒前
怕孤单的破茧完成签到,获得积分10
1秒前
niat完成签到,获得积分10
2秒前
今后的应助被Layman采纳,获得10
2秒前
3秒前
3秒前
浮爔完成签到,获得积分20
5秒前
5秒前
义气芯发布了新的文献求助10
5秒前
tefy完成签到,获得积分10
7秒前
Layman完成签到,获得积分10
9秒前
蓝天发布了新的文献求助10
9秒前
10秒前
花音发布了新的文献求助10
10秒前
翩翩雨菲完成签到,获得积分20
11秒前
11秒前
11秒前
JamesPei的应助被LIUZQ采纳,获得10
12秒前
12秒前
wing完成签到 ,获得积分10
14秒前
陈明珠发布了新的文献求助10
15秒前
zhang发布了新的文献求助10
16秒前
XX发布了新的文献求助50
17秒前
17秒前
高高冥幽的应助被heth采纳,获得10
17秒前
852的应助被ccc采纳,获得10
18秒前
Any发布了新的文献求助10
20秒前
义气芯完成签到,获得积分10
20秒前
都安完成签到,获得积分10
24秒前
24秒前
Orange的应助被成就的外套采纳,获得10
25秒前
搜集达人的应助被一颗星星草采纳,获得10
25秒前
orixero的应助被稚昂采纳,获得10
25秒前
老的火龙果的应助被wqdoctor采纳,获得10
26秒前
mys完成签到,获得积分20
26秒前
30秒前
科研通AI6.4的应助被轻松的翎采纳,获得10
30秒前
mys发布了新的文献求助10
30秒前
粗暴的季节完成签到,获得积分10
32秒前
orixero的应助被糊涂的万采纳,获得10
32秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Rosenblum, Global Change Biology 800
自動車の空力技術 800
Biographisches Lexikon der hervorragenden Ärzte der letzten fünfzig Jahre [1880–1930]. Zugleich Fortsetzung des Biographischen Lexikons der hervorragenden Ärzte aller Zeiten und Völker 600
Organizational Behavior 510
Management and the Arts 510
Issues in Task-Based Language Teaching 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 计算机科学 化学工程 工程类 有机化学 物理 复合材料 生物化学 内科学 细胞生物学 基因 遗传学 免疫学 冶金 光电子学 癌症研究
热门帖子
关注 科研通微信公众号,转发送积分 7787101
求助须知:如何正确求助?哪些是违规求助? 9325691
关于积分的说明 20406691
捐赠科研通 7376037
什么是DOI,文献DOI怎么找? 3321986
关于科研通互助平台的介绍 2469832
邀请新用户注册赠送积分活动 2338637