The PKEX protocol ( https://tools.ietf.org/html/draft-harkins-pkex-00 ) provides PAKE functionality (with SPAKE2) and adds public key authentication (PAKE+PKA). In looking at alternatives to PKEX, combining an existing and evaluated authenticated public key exchange with a PAKE seems like an interesting design path. To this end, the SPAKE2 protocol ( https://tools.ietf.org/html/draft-irtf-cfrg-spake2-03 ) combines nicely with mutually blinded Diffie-Hellman (mbDH). Blinded DH (bDH) is described in https://www.emvco.com/specifications.aspx?id=285 A brief description of the resulting SPAKE2+mbDH protocol is contained in slides 13 to 18 of: https://mentor.ieee.org/802.11/dcn/16/11-16-1142-04-00ai-cryptographic-rev iew-and-pkex.ppt Comments would be appreciated. If this protocol seems useful an RFC could be developed. Paul
