[Cfrg] PAKE Selection Process: Round 2, Stage 2

"Stanislav V. Smyshlyaev" <smyshsv@gmail.com> Mon, 09 December 2019 12:43 UTC

From: "Stanislav V. Smyshlyaev" <smyshsv@gmail.com>
Date: Mon, 9 Dec 2019 15:43:35 +0300
Message-ID: <CAMr0u6=hOG1Jw_3iafiC+0U4F6OX6Dnx78+4zamk7GmdgvvfGw@mail.gmail.com>
To: CFRG <cfrg@irtf.org>, crypto-panel@irtf.org
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/j88r8N819bw88xCOyntuw_Ych-I>
Subject: [Cfrg] PAKE Selection Process: Round 2, Stage 2
Dear CFRG,

According to the plan of Round 2 of the PAKE selection process, additional
questions for all four remaining candidates have been collected from CFRG
participants (and Crypto Review Panel members) via crypto-panel@irtf.org .

We've obtained the following list of questions:
1) (to SPAKE2): Can you propose a modification of SPAKE2 (preserving all
existing good properties of PAKE2) with a correspondingly updated security
proof, addressing the issue of a single discrete log relationship necessary
for the security of all sessions (e.g., solution based on using
M=hash2curve(A|B), N=hash2curve(B|A))?
2) (to CPace and AuCPace): Can you propose a modification of CPace and
AuCPace (preserving all existing good properties of these PAKEs) with a
correspondingly updated security proof (maybe, in some other security
models), addressing the issue of requiring the establishment of a session
identifier (sid) during each call of the protocol for the cost of one
additional message?
3) (to all 4 remaining PAKEs) : Can the nominators/developers of the
protocols please re-evaluate possible IPR conflicts between their
candidates protocols and own and foreign patents? Specifically, can you
discuss the impact of U.S. Patent 7,047,408 (expected expiration 10th of
march 2023) on free use of SPAKE2 and the impact of EP1847062B1 (HMQV,
expected expiration October 2026) on the free use of the RFC-drafts for
4) (to all 4 remaining PAKEs) What can be said about the property of
"quantum annoyance" (an attacker with a quantum computer needs to solve
[one or more] DLP per password guess) of the PAKE?
5) (to all 4 remaining PAKEs) What can be said about "post-quantum
preparedness" of the PAKE?

Please let the chairs and the Crypto Review Panel members know (before
December, 17th) if any questions (collected via  crypto-panel@irtf.org)
have been lost or misinterpreted (or something needs to be added).

Best regards,
CFRG Secretary