A Provably-Secure and Efficient Verifier-Based Anonymous Password-Authenticated Key Exchange Protocol
Xiaoyan Yang,Han Jiang,Qiuliang Xu,Mengbo Hou,Xiaochao Wei,Minghao Zhao,Kim-Kwang Raymond Choo
DOI: https://doi.org/10.1109/trustcom.2016.0124
2016-01-01
Abstract:Anonymous password-based authenticated key exchange (APAKE) protocols are a topic of ongoing research interest. However, the security of existing APAKE protocols is generally provided in the random oracle model, and in these protocols, passwords are stored in cleartext on the server. However, proofs of security in the random oracle model do not necessarily imply security in the real world. Recent high profile incidents also indicate the real risk of a server being compromised and information stored on the server leaked. Verifier-based password-authenticated key exchange (VPAKE) protocols have been identified as a viable solution to overcome such limitations. In this paper, we propose a novel verifier-based anonymous password-authenticated key exchange (VAPAKE) protocol constructed using smooth projective hashing function. The proposed protocol only involves two-round interactions for mutual implicit authentication. We then prove the security of the protocol in the standard model.