Paper 2025/1386
How to Tolerate Typos in Strong Asymmetric PAKE
Abstract
Strong asymmetric password-authenticated key exchange (saPAKE) is the gold standard for password-based authentication. When authenticating using saPAKE, the client holds a cleartext password, and the server holds only a "digest" of the password. The two parties obtain a shared session key if and only if the client password matches the password encoded in the digest. In this work we initiate the study of strong asymmetric fuzzy PAKE (safPAKE), which allows the client and server to obtain a shared session key if the client's password is "close enough" to the password encoded in the digest, according to some policy. safPAKE can be used to tolerate incidental password typos in the PAKE setting, which is becoming a standard industry practice outside the PAKE setting. Our safPAKE functionality supports any "typo policy", and our protocol is practical when there are a small number of permissible mistypings of a password.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in CRYPTO 2025
- Keywords
- pakepassword-authenticated key exchangepasswords
- Contact author(s)
-
mcquoidi @ oregonstate edu
rosulekm @ eecs oregonstate edu
xujiay @ oregonstate edu - History
- 2025-07-31: approved
- 2025-07-30: received
- See all versions
- Short URL
- https://ia.cr/2025/1386
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1386,
author = {Ian McQuoid and Mike Rosulek and Jiayu Xu},
title = {How to Tolerate Typos in Strong Asymmetric {PAKE}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1386},
year = {2025},
url = {https://eprint.iacr.org/2025/1386}
}