[Cfrg] [CFRG] PAKE selection process: Update on documentation regarding CPace and AuCPace

"Björn Haase" <Bjoern.M.Haase@web.de> Fri, 07 February 2020 19:05 UTC

Return-Path: <Bjoern.M.Haase@web.de>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 206CA1200FA for <cfrg@ietfa.amsl.com>; Fri, 7 Feb 2020 11:05:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.697
X-Spam-Level:
X-Spam-Status: No, score=-2.697 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=web.de
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZvEGCMZVrAcy for <cfrg@ietfa.amsl.com>; Fri, 7 Feb 2020 11:05:11 -0800 (PST)
Received: from mout.web.de (mout.web.de [212.227.15.3]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BA9721200F4 for <cfrg@irtf.org>; Fri, 7 Feb 2020 11:05:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=dbaedf251592; t=1581102307; bh=LNP1En8/bajSWkiIk7oshOffiblOsME98IUvHkftYf8=; h=X-UI-Sender-Class:From:To:Subject:Date; b=cudk3e7tbqVjldP6m3rowzoZAdOKLHT0ue3TESeqMYeouDWTZITFgeMNK2QC9Qp8Y PKaDBT9IMaWjw5CcKENX360zDnX+n5AG4SH+9FuQ1PtQCFgpi4mHS6O0EtzWu1KQq3 fXzdT32tIKv2UghOnizAa0S4w+zFo08LhsTZ9s3E=
X-UI-Sender-Class: c548c8c5-30a9-4db5-a2e7-cb6cb037b8f9
Received: from [188.110.251.139] ([188.110.251.139]) by web-mail.web.de (3c-app-webde-bs19.server.lan [172.19.170.19]) (via HTTP); Fri, 7 Feb 2020 20:05:07 +0100
MIME-Version: 1.0
Message-ID: <trinity-277932c7-5fc1-4afd-b990-3bcc13189284-1581102307483@3c-app-webde-bs19>
From: "\"Björn Haase\"" <Bjoern.M.Haase@web.de>
To: "cfrgirtf.org" <cfrg@irtf.org>
Content-Type: text/plain; charset="UTF-8"
Date: Fri, 07 Feb 2020 20:05:07 +0100
Importance: normal
Sensitivity: Normal
Content-Transfer-Encoding: quoted-printable
X-Priority: 3
X-Provags-ID: V03:K1:+KaUDNgGloxPVLUHDhYkdNDBz1KZWOWJV7z5JD3GjSqkdbMvuEiAQs5qB00prsRsXj1eC EWjlcMvtcb/TkU3ZRqqpLP3njXVakj9Y+guwpmM2PeXnam83xmB0DW3lA4u16NX4Zh4X6Nz6w3y1 cB+X72ocj8PaZp1AlwKnPzhZXUyIAMXWML/dHQ1CzU8G83W4BucNFR1BA1gVKX6xSoDPb+bHqvrG 9mQ6BZR7IoJfZTa3INakCSdB3/8v1JudNGWdSX59rNzpVZixbCriYL3jRD987BvToU9VD9WQSrbT TA=
X-UI-Out-Filterresults: notjunk:1;V03:K0:o+xeY1F0wiE=:IYbx15OTT1wLIHD8NIYgIs 8CNaPnEtKt1WADrpolD081RuS/fTw7qqSNzMhm9Py3SDo9ouK06CLIywFKh0qfH6vboKa4JiX 49fvwu3NpWhbvUqYFq0ZUhhG/ZyneCFvGMl+PHbLejYcDGDNvUJov/C52loqSdaUTiAp9HkAG wCLm8WPRJNyqjKP5nDCvYA/G5PS4BPt+C6ed/gIKO8HC15JbUdq8uA1qXOZoEXrfpzcxp3M9O /axbqm43CTP1bP9GJWN3m4YXIVrgqT/BDpyZFfocPXnm7bAPxpCNTT3C+We1nZI3/I+iQBc44 jpk8jqS7kchHV/2FN2GyQ86oTWIJpMXIjlk9tBvAwTewlkzsaihhtBB0A1UVI5vWw+Yl2dMcc G66YG7YpFFAR2ZOCXdG9vy30NtRr4d8zD5pyzfqcTLIqX/ad6bm3LCtYcLwxt/jqpU/AhkRSF Rj4XIHwOXzKBq6gLgSPziB/39K/SVdVRgXBX1PnifxD0r8CUMBZuupg9I5hH3wEnlgmxDQnOS KMYXeqzXUJ7VbFTTv+qQT8fskzAiYIbI75fwAA0ZWxco02690mgtn6YtAE3aWHbNGuKt6Vwva 9AUmcnIOpkgLnTiurWhNhyk+kys/Ofd7p1UdqhSWxzZjBXTxF9RiFXtz7vKv5Mj7dsPREyDW1 cC7vnPYAd9KCsZJBFsG/rf+lSNd9yELV+WV1H5hvtsVxVv/amWO8KK1zIUKK09THGpvU=
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/jFilUyxC-Nqm4b33hJDxCYOZMWo>
Subject: [Cfrg] [CFRG] PAKE selection process: Update on documentation regarding CPace and AuCPace
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Fri, 07 Feb 2020 19:05:13 -0000

Hi CFRG,

I would like to give notice of the changes in documentation regarding CPace and AuCPace.
 
https://tools.ietf.org/html/draft-haase-aucpace-01
https://tools.ietf.org/html/draft-haase-cpace-01

Differences in the CPace draft 01: 

The CPace text is slightly rephrased and now refers to the acronym SDH as the
simultaneous Diffie-Hellmann problem (as defined and analyzed in the VTBPEKE paper).
Notation has been modified at some places in order to be in line with a reworked
paper with the security proof that considers the last recommendations of round 1.
(To be submitted this week-end).

Differences in the AuCPace draft 01:
 
I have added the process of AuCPace-authenticated transactions, such as useful for
change-passwords and "sudo"-style transactions. I moreover have fixed a bug in the
test vector section that stemmed from the fact that some python implementations of
scrypt seem to have problems with non-ASCII characters in the salt field.

Moreover, I have setup a repository with reference implementations for SageMath and C.
Code is available at 
https://github.com/BjoernMHaase/AuCPace

Yours,

Björn.