We present the first round-optimal PPSS scheme, requiring just one message from user to server, and from server to user, and that works in the password-only setting where users do not have access to an authenticated public key. The scheme uses an Oblivious PRF whose security we define using a UC-style ideal functionality and denote as V-OPRF due to its verifiability, and for which we show concrete, very practical realizations in the random oracle model, as well as standard-model instantiations. As an important application we use this scheme to build the first single-round password-only Threshold-PAKE protocol in the CRS and ROM models for arbitrary (t,n) parameters with no PKI requirements for any party (clients or servers) and no inter-server communication. Our T-PAKE protocols are built by combining suitable key exchange protocols on top of our V-OPRF-based PPSS schemes. We prove T-PAKE security via a generic composition theorem showing the security of any such composed protocol.
Category / Keywords: cryptographic protocols / password authentication, secret sharing Date: received 21 Aug 2014 Contact author: stanislawjarecki at gmail com Available format(s): PDF | BibTeX Citation Version: 20140827:073706 (All versions of this report) Short URL: ia.cr/2014/650 Discussion forum: Show discussion | Start new discussion