The field of Password-Authenticated Key Exchange (PAKE) protocols has been actively explored for more than three decades, and it was not until 2020 that the IRTF working group CFRG selected the CPace protocol as the recommended PAKE standard. The Universally Composable (UC) security of CPace has been comprehensively studied by Abdalla et al. (ASIACRYPT’21). However, typical UC models do not capture cryptographic subversion attacks which could manipulate the cryptographic implementations to leak some secret covertly. To achieve subversion-resilience in UC models, Chakraborty et al. (EUROCRYPT’22) and Arnold et al. (Eprint 2023/1951) both extended reverse firewalls (Mironov and Stephens-Davidowitz, EUROCRYPT’15) to the UC setting with different considerations. In this work, we propose a subversion-resilient PAKE protocol, called srCPace, that UC-realizes a lazy-extraction PAKE functionality under subversion corruption. Note that current models (both Chakraborty et al.’s model and Arnold et al.’s) assume the existence of authenticated channels while PAKE protocols typically run on unauthenticated channels. To close the gap, we revisit the main theorem of Arnold et al. in the setting of unauthenticated communication. Then, we modify the CPace protocol to support particular reverse firewalls. Finally, by equipping the modified CPace with reverse firewalls, we obtain srCPace and prove its UC security with subversion-resilience by applying our adapted theorem. Our protocol enhances the security of CPace when deployed in the real world where implementations might be corrupted.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

srCPace: Universally Composable PAKE with Subversion-Resilience

  • Jiahao Liu,
  • Yi Wang,
  • Rongmao Chen,
  • Xincheng Tang,
  • Jinshu Su

摘要

The field of Password-Authenticated Key Exchange (PAKE) protocols has been actively explored for more than three decades, and it was not until 2020 that the IRTF working group CFRG selected the CPace protocol as the recommended PAKE standard. The Universally Composable (UC) security of CPace has been comprehensively studied by Abdalla et al. (ASIACRYPT’21). However, typical UC models do not capture cryptographic subversion attacks which could manipulate the cryptographic implementations to leak some secret covertly. To achieve subversion-resilience in UC models, Chakraborty et al. (EUROCRYPT’22) and Arnold et al. (Eprint 2023/1951) both extended reverse firewalls (Mironov and Stephens-Davidowitz, EUROCRYPT’15) to the UC setting with different considerations. In this work, we propose a subversion-resilient PAKE protocol, called srCPace, that UC-realizes a lazy-extraction PAKE functionality under subversion corruption. Note that current models (both Chakraborty et al.’s model and Arnold et al.’s) assume the existence of authenticated channels while PAKE protocols typically run on unauthenticated channels. To close the gap, we revisit the main theorem of Arnold et al. in the setting of unauthenticated communication. Then, we modify the CPace protocol to support particular reverse firewalls. Finally, by equipping the modified CPace with reverse firewalls, we obtain srCPace and prove its UC security with subversion-resilience by applying our adapted theorem. Our protocol enhances the security of CPace when deployed in the real world where implementations might be corrupted.