Paper 2025/1343

A Hybrid Asymmetric Password-Authenticated Key Exchange in the Random Oracle Model

Jelle Vos, Apple (United States)
Stanislaw Jarecki, University of California, Irvine
Christopher A. Wood, Apple (United States)
Cathie Yun, Apple (United States)
Steve Myers, Apple (United States)
Yannick Sierra, Apple (United States)
Abstract

Symmetric encryption allows us to establish a secure channel based on a shared, strong key. However, users cannot remember or cannot store such keys securely. Password-Authenticated Key Exchange (PAKE) protocols address this by using low-entropy, human-memorizable passwords to establish secure channels. PAKEs are widely used and are foundational in practical cryptographic protocols, but while cryptographic tools like Key Encapsulation Mechanism (KEM) and Signatures have been implemented to resist attacks from quantum computers, PAKEs have gained quantum security only recently. To hedge against any potential vulnerabilities in recent quantum-secure PAKEs and in their implementations, we primarily focus on hybrid PAKE constructions that compose CPace, a classically-secure PAKE, with a variant of a recently proposed quantum-secure PAKE, which we call OQUAKE. Specifically we introduce and analyze two new hybrid PAKEs designed to be efficient, easy to implement, and utilize a minimized set of standard building blocks. The first, called CPaceOQUAKE, is a hybrid symmetric PAKE that remains secure as long as either a classical or post-quantum assumption holds. The second, called CPaceOQUAKE+, is a hybrid asymmetric PAKE (aPAKE) where the server party holds a verifier that obscures the password, instead of holding the password itself. In our analysis we present the necessary security proofs in the Universal Composability framework. In particular, we prove that OQUAKE, the underlying KEM-based PAKE in our hybrid constructions, realizes a relaxed UC PAKE variant that exposes password equality to passive observers, an observation available anyway in typical applications of PAKEs where the network interactions which follow the PAKE depend on authentication success. Moreover, we prove that our variant of the PAKE(+KEM)-to-aPAKE compiler is a similarly relaxed UC aPAKE.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
Post-quantum cryptographyPassword-authenticated key exchangePAKEaPAKEKEM
Contact author(s)
mail @ jelle-vos nl
stanislawjarecki @ gmail com
caw @ heapingbits net
cathieyun @ gmail com
History
2025-07-23: approved
2025-07-23: received
See all versions
Short URL
https://ia.cr/2025/1343
License
Creative Commons Attribution-NonCommercial-NoDerivs
CC BY-NC-ND

BibTeX

@misc{cryptoeprint:2025/1343,
      author = {Jelle Vos and Stanislaw Jarecki and Christopher A. Wood and Cathie Yun and Steve Myers and Yannick Sierra},
      title = {A Hybrid Asymmetric Password-Authenticated Key Exchange in the Random Oracle Model},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1343},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1343}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.