{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T15:09:09Z","timestamp":1779203349417,"version":"3.51.4"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031305887","type":"print"},{"value":"9783031305894","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-30589-4_4","type":"book-chapter","created":{"date-parts":[[2023,4,15]],"date-time":"2023-04-15T11:02:07Z","timestamp":1681556527000},"page":"98-127","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Password-Authenticated TLS via\u00a0OPAQUE and\u00a0Post-Handshake Authentication"],"prefix":"10.1007","author":[{"given":"Julia","family":"Hesse","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stanislaw","family":"Jarecki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hugo","family":"Krawczyk","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Wood","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,4,16]]},"reference":[{"key":"4_CR1","unstructured":"Facebook stored hundreds of millions of passwords in plain text (2019). https:\/\/www.theverge.com\/2019\/3\/21\/18275837\/facebook-plain-text-password-storage-hundreds-millions-users"},{"key":"4_CR2","unstructured":"Google stored some passwords in plain text for fourteen years (2019). https:\/\/www.theverge.com\/2019\/5\/21\/18634842\/google-passwords-plain-text-g-suite-fourteen-years"},{"key":"4_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1007\/11542322_6","volume-title":"Security Protocols","author":"N Asokan","year":"2005","unstructured":"Asokan, N., Niemi, V., Nyberg, K.: Man-in-the-middle in tunnelled authentication protocols. In: Christianson, B., Crispo, B., Malcolm, J.A., Roe, M. (eds.) Security Protocols 2003. LNCS, vol. 3364, pp. 28\u201341. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11542322_6"},{"key":"4_CR4","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Blanchet, B., Kobeissi, N.: Verified models and reference implementations for the TLS 1.3 standard candidate. In: IEEE Symposium on Security and Privacy, pp. 483\u2013502. IEEE Computer Society (2017)","DOI":"10.1109\/SP.2017.26"},{"key":"4_CR5","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Delignat-Lavaud, A., Fournet, C., Pironti, A., Strub, P.-Y.: Triple handshakes and cookie cutters: breaking and fixing authentication over TLS. In: IEEE Symposium on Security and Privacy, pp. 98\u2013113. IEEE Computer Society (2014)","DOI":"10.1109\/SP.2014.14"},{"key":"4_CR6","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Delignat-Lavaud, A., Pironti, A.: Verified contributive channel bindings for compound authentication. In: NDSS (2015)","DOI":"10.14722\/ndss.2015.23277"},{"key":"4_CR7","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Leurent, G.: Transcript collision attacks: breaking authentication in TLS, IKE and SSH. In: 23rd Annual Network and Distributed System Security Symposium, NDSS (2016)","DOI":"10.14722\/ndss.2016.23418"},{"key":"4_CR8","doi-asserted-by":"crossref","unstructured":"Blanchet, B.: An efficient cryptographic protocol verifier based on prolog rules. In: IEEE Computer Security Foundations Workshop CSFW-14, pp. 82\u201396. IEEE Computer Society (2001)","DOI":"10.1109\/CSFW.2001.930138"},{"key":"4_CR9","unstructured":"Bourdrez, D., Krawczyk, H., Lewi, K., Wood, C.: The OPAQUE Asymmetric PAKE Protocol, draft-irtf-cfrg-opaque, July 2022. https:\/\/tools.ietf.org\/id\/draft-irtf-cfrg-opaque"},{"key":"4_CR10","doi-asserted-by":"crossref","unstructured":"Brzuska, C., Jacobsen, H.: A modular security analysis of EAP and IEEE 802.11. In: Cryptology ePrint Archive, Paper 2017\/253 (PKC 2017) (2017)","DOI":"10.1007\/978-3-662-54388-7_12"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Canetti, R., Universally composable security: a new paradigm for cryptographic protocols. In: IEEE Symposium on Foundations of Computer Science - FOCS 2001, pp. 136\u2013145. IEEE (2001)","DOI":"10.1109\/SFCS.2001.959888"},{"key":"4_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/3-540-46035-7_22","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2002","author":"R Canetti","year":"2002","unstructured":"Canetti, R., Krawczyk, H.: Universally composable notions of key exchange and secure channels. In: Knudsen, L.R. (ed.) EUROCRYPT 2002. LNCS, vol. 2332, pp. 337\u2013351. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-46035-7_22"},{"key":"4_CR13","doi-asserted-by":"crossref","unstructured":"Cremers, C., Horvat, M., Scott, S., van der Merwe, T.: Automated analysis and verification of TLS 1.3: 0-rtt, resumption and delayed authentication. In: IEEE Symposium on Security and Privacy, pp. 470\u2013485. IEEE Computer Society (2016)","DOI":"10.1109\/SP.2016.35"},{"key":"4_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/11818175_9","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"C Gentry","year":"2006","unstructured":"Gentry, C., MacKenzie, P., Ramzan, Z.: A method for making password-based key exchange resilient to server compromise. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol. 4117, pp. 142\u2013159. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_9"},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Hesse, J., Jarecki, S., Krawczyk, H.: Password-authenticated tls via opaque and post-handshake authentication. Cryptology ePrint Archive, Report 2023\/220 (2023). https:\/\/ia.cr\/2023\/220","DOI":"10.1007\/978-3-031-30589-4_4"},{"key":"4_CR16","unstructured":"Hodges, J., Jones, J.C., Jones, M.B., Kumar, A., Lundberg, E.: Web authentication: an API for accessing public key credentials level 2, August 2021. https:\/\/www.w3.org\/TR\/webauthn-2\/"},{"key":"4_CR17","unstructured":"Hoyland, J.: An analysis of TLS 1.3 and its use in composite protocols. Ph.D. thesis, RHUL, Egham, UK (2018)"},{"key":"4_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"456","DOI":"10.1007\/978-3-319-78372-7_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"S Jarecki","year":"2018","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10822, pp. 456\u2013486. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15"},{"key":"4_CR19","unstructured":"Krawczyk, H.: The OPAQUE Asymmetric PAKE Protocol, draft-krawczyk-cfrg-opaque-06, June 2020. https:\/\/www.ietf.org\/archive\/id\/draft-krawczyk-cfrg-opaque-06.txt"},{"key":"4_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"631","DOI":"10.1007\/978-3-642-14623-7_34","volume-title":"Advances in Cryptology \u2013 CRYPTO 2010","author":"H Krawczyk","year":"2010","unstructured":"Krawczyk, H.: Cryptographic extraction and key derivation: the HKDF scheme. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 631\u2013648. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_34"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Krawczyk, H.: Unilateral-to-mutual authentication compiler for key exchange (with applications to client authentication in tls 1.3). In: ACM CCS 2016 (2016)","DOI":"10.1145\/2976749.2978325"},{"key":"4_CR22","unstructured":"Ray, M., Dispensa, S.: Authentication gap in tls renegotiation (2009)"},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The transport layer security (TLS) protocol version 1.3, rfc 8446, August 2018. http:\/\/www.rfc-editor.org\/rfc\/rfc8446.txt","DOI":"10.17487\/RFC8446"},{"key":"4_CR24","unstructured":"Rex, M.: Mitm attack on delayed TLS-client auth through renegotiation, November 2009"},{"key":"4_CR25","unstructured":"Salowey, J., Rescorla, E.: TLS renegotiation vulnerability (2009)"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Sullivan, N.: Exported Authenticators in TLS, RFC 9261, July 2022. https:\/\/datatracker.ietf.org\/doc\/html\/rfc9261","DOI":"10.17487\/RFC9261"},{"key":"4_CR27","unstructured":"Sullivan, N., Krawczyk, H., Friel, O., Barnes, R.: OPAQUE with TLS 1.3, draft-sullivan-tls-opaque-01, February 2021. https:\/\/datatracker.ietf.org\/doc\/html\/draft-sullivan-tls-opaque"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2023"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-30589-4_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,15]],"date-time":"2025-04-15T22:04:24Z","timestamp":1744754664000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-30589-4_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031305887","9783031305894"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-30589-4_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"16 April 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lyon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 April 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"42","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"415","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"109","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"16","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}