Paper 2025/1519

Does the UC-Security Notion for PAKE Imply Game-Based Security?

Jiayu Xu, Oregon State University
Abstract

A Password-Authenticated Key Exchange (PAKE) protocol allows two parties to jointly establish a cryptographically strong key, in the setting where the only information shared in advance is a low-entropy "password". The two standard security definitions for PAKE are the game-based one by Bellare, Pointcheval and Rogaway (BPR-security, EUROCRYPT 2000) and the Universally Composable (UC) one by Canetti et al. (EUROCRYPT 2005). It is well-known that UC-security implies BPR-security; however, there are a large number of variants of both definitions, and the relation between them is not entirely clear. In this work, we thoroughly study a variant of BPR-security by Katz, Ostrovsky and Yung (KOY-security, JACM 2009): 1. We show, via a counterexample, that UC-security does \emph{not} imply KOY-security; 2. We then prove that a variant of UC-security, called implicit-only UC-security (Dupont et al., EUROCRYPT 2018), implies KOY-security. Interestingly, we make the observation that KOY- and implicit-only UC-security essentially strengthen their standard counterparts in the same manner. We also present detailed explanations of all four security notions.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published by the IACR in CIC 2025
Contact author(s)
xujiay @ oregonstate edu
History
2025-12-25: revised
2025-08-24: received
See all versions
Short URL
https://ia.cr/2025/1519
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1519,
      author = {Jiayu Xu},
      title = {Does the {UC}-Security Notion for {PAKE} Imply Game-Based Security?},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1519},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1519}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.