Paper 2024/374

Universal Composable Password Authenticated Key Exchange for the Post-Quantum World

You Lyu, Shanghai Jiao Tong University
Shengli Liu, Shanghai Jiao Tong University
Shuai Han, Shanghai Jiao Tong University
Abstract

In this paper, we construct the first password authenticated key exchange (PAKE) scheme from isogenies with Universal Composable (UC) security in the random oracle model (ROM). We also construct the first two PAKE schemes with UC security in the quantum random oracle model (QROM), one is based on the learning with error (LWE) assumption, and the other is based on the group-action decisional Diffie- Hellman (GA-DDH) assumption in the isogeny setting. To obtain our UC-secure PAKE scheme in ROM, we propose a generic construction of PAKE from basic lossy public key encryption (LPKE) and CCA-secure PKE. We also introduce a new variant of LPKE, named extractable LPKE (eLPKE). By replacing the basic LPKE with eLPKE, our generic construction of PAKE achieves UC security in QROM. The LPKE and eLPKE have instantiations not only from LWE but also from GA-DDH, which admit four specific PAKE schemes with UC security in ROM or QROM, based on LWE or GA-DDH.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
A major revision of an IACR publication in EUROCRYPT 2024
Keywords
PAKEPost Quantum Security
Contact author(s)
vergil @ sjtu edu cn
slliu @ sjtu edu cn
dalen17 @ sjtu edu cn
History
2024-03-01: approved
2024-02-29: received
See all versions
Short URL
https://ia.cr/2024/374
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2024/374,
      author = {You Lyu and Shengli Liu and Shuai Han},
      title = {Universal Composable Password Authenticated Key Exchange for the Post-Quantum World},
      howpublished = {Cryptology ePrint Archive, Paper 2024/374},
      year = {2024},
      note = {\url{https://eprint.iacr.org/2024/374}},
      url = {https://eprint.iacr.org/2024/374}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.