Password-Authenticated Asymmetric Key Exchange Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password-based authenticated key exchange (PB-AKE) protocols are vulnerable to dictionary attacks and man-in-the-middle attacks, especially when weak passwords are used, and they require additional cryptography to ensure security, which can be cumbersome, particularly for central servers that need to authenticate users without storing actual passwords.

Innovation Solution

The implementation of password-authenticated asymmetric key exchange (PAAKE) methods using asymmetric cryptographic techniques, where keys are encrypted and decrypted using different password-based keys derived from the same password, ensuring secure authentication and key exchange without revealing the password, and incorporating a third public prime in the PAAKE modulus to prevent guessing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password-based authenticated key exchange protocols are used, then authentication between parties is enabled, but the protocols become vulnerable to dictionary attacks and man-in-the-middle attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to dictionary attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by using asymmetric cryptographic techniques where a first key (private key) and second key (public key) are mathematically related but not identical. The first key encrypts exchange keys and the second key decrypts them, creating an asymmetric authentication mechanism that prevents dictionary attacks while maintaining password-based authentication.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent changes the cryptographic parameters by introducing a PAAKE modulus incorporating a third public prime, moving beyond traditional symmetric password-based approaches. This parameter change enables the system to achieve both authentication and resistance to dictionary attacks simultaneously.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If strong cryptography is used in PB-AKE to prevent dictionary attacks, then security is improved, but the protocol becomes cumbersome and complex

Engineering Contradiction:
Improvesecurity against dictionary attacksVSAvoidcryptographic protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges password-based authentication with asymmetric cryptography into a unified PAAKE protocol. By combining these approaches, the system achieves strong security without requiring separate authentication and key exchange protocols, reducing overall complexity while maintaining robust security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The PAAKE protocol serves multiple functions simultaneously: it provides authentication, enables key exchange, and prevents dictionary attacks all within a single protocol framework. This multi-functionality eliminates the need for additional cryptographic layers that would increase complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If central servers store actual passwords for user authentication, then authentication is simplified, but the risk of password exposure and database theft increases

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidrisk of password exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the server's storage requirements by using asymmetric keys derived from passwords. The server stores only cryptographic artifacts (public keys, moduli) rather than actual passwords, removing the vulnerable element while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic intermediaries (asymmetric key pairs and PAAKE modulus) that mediate between the password and the authentication process. These intermediaries allow the server to verify user identity without ever storing or handling actual passwords, eliminating the security risk while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8225095B2Password-authenticated asymmetric key exchange
Publication Date: 2012.07.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8225095B2 patent drawing
  • US8225095B2 patent drawing
  • US8225095B2 patent drawing

AI summary

Communicating keys between network devices on a network using asymmetric cryptographic techniques, for which asymmetric keys may be derived from a single (same) password. Knowledge or partial knowledge of the password may be the only information shared between parties prior to execution of a key exchange, and may be the only criteria by which one party will base trust in the other. A first network device may encrypt a key using a password-based key derived from a password, and authenticate a second device based on the second network device's ability to decrypt the encrypted key using a key derived from the same password. Knowledge of the password may be conveyed by the second device to the first device—a session key may be generated as a function of the decrypted key, and a function of this session key may be communicated from the second device to the first device.