srCPace: Universally Composable PAKE with Subversion-Resilience
摘要
The field of Password-Authenticated Key Exchange (PAKE) protocols has been actively explored for more than three decades, and it was not until 2020 that the IRTF working group CFRG selected the CPace protocol as the recommended PAKE standard. The Universally Composable (UC) security of CPace has been comprehensively studied by Abdalla et al. (ASIACRYPT’21). However, typical UC models do not capture cryptographic subversion attacks which could manipulate the cryptographic implementations to leak some secret covertly. To achieve subversion-resilience in UC models, Chakraborty et al. (EUROCRYPT’22) and Arnold et al. (Eprint 2023/1951) both extended reverse firewalls (Mironov and Stephens-Davidowitz, EUROCRYPT’15) to the UC setting with different considerations. In this work, we propose a subversion-resilient PAKE protocol, called srCPace, that UC-realizes a lazy-extraction PAKE functionality under subversion corruption. Note that current models (both Chakraborty et al.’s model and Arnold et al.’s) assume the existence of authenticated channels while PAKE protocols typically run on unauthenticated channels. To close the gap, we revisit the main theorem of Arnold et al. in the setting of unauthenticated communication. Then, we modify the CPace protocol to support particular reverse firewalls. Finally, by equipping the modified CPace with reverse firewalls, we obtain srCPace and prove its UC security with subversion-resilience by applying our adapted theorem. Our protocol enhances the security of CPace when deployed in the real world where implementations might be corrupted.