Password-Authenticated Asymmetric Key Exchange Protocol
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password-based authenticated key exchange (PB-AKE) protocols are vulnerable to dictionary attacks and man-in-the-middle attacks, especially when weak passwords are used, and they require additional cryptography to ensure security, which can be cumbersome, particularly for central servers that need to authenticate users without storing actual passwords.
Innovation Solution
The implementation of password-authenticated asymmetric key exchange (PAAKE) methods using asymmetric cryptographic techniques, where keys are encrypted and decrypted using different password-based keys derived from the same password, ensuring secure authentication and key exchange without revealing the password, and incorporating a third public prime in the PAAKE modulus to prevent guessing attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authenticated key exchange protocols are used, then authentication between parties is enabled, but the protocols become vulnerable to dictionary attacks and man-in-the-middle attacks
Solution Approach 1:
The patent applies asymmetry by using asymmetric cryptographic techniques where a first key (private key) and second key (public key) are mathematically related but not identical. The first key encrypts exchange keys and the second key decrypts them, creating an asymmetric authentication mechanism that prevents dictionary attacks while maintaining password-based authentication.
Solution Approach 2:
The patent changes the cryptographic parameters by introducing a PAAKE modulus incorporating a third public prime, moving beyond traditional symmetric password-based approaches. This parameter change enables the system to achieve both authentication and resistance to dictionary attacks simultaneously.
2Reliability
If strong cryptography is used in PB-AKE to prevent dictionary attacks, then security is improved, but the protocol becomes cumbersome and complex
Solution Approach 1:
The patent merges password-based authentication with asymmetric cryptography into a unified PAAKE protocol. By combining these approaches, the system achieves strong security without requiring separate authentication and key exchange protocols, reducing overall complexity while maintaining robust security.
Solution Approach 2:
The PAAKE protocol serves multiple functions simultaneously: it provides authentication, enables key exchange, and prevents dictionary attacks all within a single protocol framework. This multi-functionality eliminates the need for additional cryptographic layers that would increase complexity.
3Ease of operation
If central servers store actual passwords for user authentication, then authentication is simplified, but the risk of password exposure and database theft increases
Solution Approach 1:
The patent extracts the password from the server's storage requirements by using asymmetric keys derived from passwords. The server stores only cryptographic artifacts (public keys, moduli) rather than actual passwords, removing the vulnerable element while preserving authentication functionality.
Solution Approach 2:
The patent introduces cryptographic intermediaries (asymmetric key pairs and PAAKE modulus) that mediate between the password and the authentication process. These intermediaries allow the server to verify user identity without ever storing or handling actual passwords, eliminating the security risk while maintaining operational simplicity.
Data Source
AI summary
Communicating keys between network devices on a network using asymmetric cryptographic techniques, for which asymmetric keys may be derived from a single (same) password. Knowledge or partial knowledge of the password may be the only information shared between parties prior to execution of a key exchange, and may be the only criteria by which one party will base trust in the other. A first network device may encrypt a key using a password-based key derived from a password, and authenticate a second device based on the second network device's ability to decrypt the encrypted key using a key derived from the same password. Knowledge of the password may be conveyed by the second device to the first device—a session key may be generated as a function of the decrypted key, and a function of this session key may be communicated from the second device to the first device.


