Paper 2025/119

SoK: PQC PAKEs - Design, Security and Performance

Nouri Alnahawi, Darmstadt University of Applied Sciences
David Haas, TU Darmstadt
Erik Mauß, Darmstadt University of Applied Sciences
Alexander Wiesmaier, Darmstadt University of Applied Sciences
Abstract

Password Authenticated Key Exchange (PAKE) establishes secure communication channels using passwords for authentication. Currently, standardized PAKEs rely on classical asymmetric cryptography. However, these PAKEs may become insecure should the expected quantum threat become a reality. Despite the growing interest in realizing quantum-safe PAKEs, they did not receive much attention from the ongoing Post-Quantum Cryptography (PQC) integration efforts. Hence, there is a significant awareness gap compared to PQC primitives subject to the official standardization processes. We provide a comprehensive overview of existing PQC PAKEs, classify their design rationales and authentication methods, and address aspects related to their security and performance. We identify PAKE designs that are still unexplored in the PQC realm and discuss the possibility of their adaptation. Thus, we offer a detailed reference for future work on PQC PAKEs.

Note: Updated title and author affiliations. Major Revision into Long Paper. Added new references and updated published eprints.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Systematization of KnowledgePassword Authenticated Key ExchangePost-Quantum CryptographyPublic-Key Cryptography
Contact author(s)
nouri alnahawi @ h-da de
david haas1 @ stud tu-darmstadt de
erik mauss @ stud h-da de
alexander wiesmaier @ h-da de
History
2025-10-20: last of 7 revisions
2025-01-26: received
See all versions
Short URL
https://ia.cr/2025/119
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/119,
      author = {Nouri Alnahawi and David Haas and Erik Mauß and Alexander Wiesmaier},
      title = {{SoK}: {PQC} {PAKEs} - Design, Security and Performance},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/119},
      year = {2025},
      url = {https://eprint.iacr.org/2025/119}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.