Paper 2025/1598

How to kickstart Secure Message Transfer with Short Authentication Strings and Out-Of-Band Communication

Wasilij Beskorovajnov, Research Center for Information Technology
Jörn Müller-Quade, Karlsruhe Institute of Technology
Abstract

We study “send this data to that device now” exchanges under an active network adversary without PKI or pre-shared secrets. We model a human-verifiable out-of-band channel for comparing short codes as a first-class UC functionality. Building on this, we give two commitment-style protocols, a one-sided and a mutual one, that are direct UC equivalents of MANA-IV and prove they realize authenticated channels with explicit misbinding parameter \(\varepsilon=2^{-t}\). We then compose SAS-based authentication with standard KEM/DEM encryption to obtain a UC-secure message-transfer functionality, preserving the explicit \(\varepsilon\) under composition, and we detail practical instantiations over signatures or MACs. Complementing the theory, we systematize real-world tooling: popular file-transfer utilities either form unauthenticated WebRTC/DTLS channels or use PAKE “one-code” designs that couple rendezvous and a longer password string but none deploy a session-bound SAS. Our approach decouples rendezvous from authentication and reduces the out-of-band burden to comparing a short \(t\)-bit string. We also sketch an RO-free variant (coin-flip plus non-malleable commitments) with the same user interface.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Preprint.
Keywords
SASUCSMTMANA-IVRandom OracleAuthenticationConfidentialityOut-of-BandUser-Aided
Contact author(s)
Beskorovajnov @ fzi de
mueller-quade @ kit edu
History
2025-09-11: last of 2 revisions
2025-09-05: received
See all versions
Short URL
https://ia.cr/2025/1598
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1598,
      author = {Wasilij Beskorovajnov and Jörn Müller-Quade},
      title = {How to kickstart Secure Message Transfer with Short Authentication Strings and Out-Of-Band Communication},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1598},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1598}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.