Strong password-only authenticated key exchange

  • Authors:
  • David P. Jablon

  • Affiliations:
  • Integrity Sciences, Inc., Westboro, MA

  • Venue:
  • ACM SIGCOMM Computer Communication Review
  • Year:
  • 1996

Quantified Score

Hi-index 0.00

Visualization

Abstract

A new simple password exponential key exchange method (SPEKE) is described. It belongs to an exclusive class of methods which provide authentication and key establishment over an insecure channel using only a small password, without risk of offline dictionary attack. SPEKE and the closely-related Diffie-Hellman Encrypted Key Exchange (DH-EKE) are examined in light of both known and new attacks, along with sufficient preventive constraints. Although SPEKE and DH-EKE are similar, the constraints are different. The class of strong password-only methods is compared to other authentication schemes. Benefits, limitations, and tradeoffs between efficiency and security are discussed. These methods are important for several uses, including replacement of obsolete systems, and building hybrid two-factor systems where independent password-only and key-based methods can survive a single event of either key theft or password compromise.