The password-based key exchange protocol shown here is in the common reference string model and relies on standard number-theoretic assumptions. The components of our protocol can be instantiated to give a relatively efficient solution which is conceivably usable in practice. We also show that it is impossible to satisfy our definition in the "plain" model (e.g., without a common reference string).
Category / Keywords: cryptographic protocols / key exchange, password protocols, universal composability Publication Info: Extended abstract in EUROCRYPT '05. LNCS vol. 3494, pages 404-421. Springer-Verlag, 2005 Date: received 24 Jun 2005 Contact author: shaih at alum mit edu Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation Version: 20050624:183557 (All versions of this report) Short URL: ia.cr/2005/196 Discussion forum: Show discussion | Start new discussion