{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T00:28:29Z","timestamp":1786753709293,"version":"3.56.0"},"publisher-location":"Cham","reference-count":81,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031683787","type":"print"},{"value":"9783031683794","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-68379-4_7","type":"book-chapter","created":{"date-parts":[[2024,8,15]],"date-time":"2024-08-15T16:17:23Z","timestamp":1723738643000},"page":"218-250","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["LATKE: A Framework for\u00a0Constructing Identity-Binding PAKEs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6084-9303","authenticated-orcid":false,"given":"Jonathan","family":"Katz","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9784-125X","authenticated-orcid":false,"given":"Michael","family":"Rosenberg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,8,16]]},"reference":[{"key":"7_CR1","unstructured":"Welcome to the OpenWrt Project. https:\/\/openwrt.org"},{"key":"7_CR2","doi-asserted-by":"publisher","unstructured":"Abdalla, M., Eisenhofer, T., Kiltz, E., Kunzweiler, S., Riepel, D.: Password-authenticated key exchange from group actions. In: Dodis and Shrimpton [44], pp. 699\u2013728. Springer, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-031-15979-4_24","DOI":"10.1007\/978-3-031-15979-4_24"},{"key":"7_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1007\/978-3-030-92068-5_24","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"M Abdalla","year":"2021","unstructured":"Abdalla, M., Haase, B., Hesse, J.: Security analysis of\u00a0CPace. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 711\u2013741. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_24"},{"key":"7_CR4","unstructured":"Alkim, E., Ducas, L., P\u00f6ppelmann, T., Schwabe, P.: Post-quantum key exchange - a new hope. In: Holz, T., Savage, S. (eds.) USENIX Security 2016, pp. 327\u2013343. USENIX Association (2016)"},{"key":"7_CR5","unstructured":"Alliance, C.S.: Matter Specification v1.0 (2022). https:\/\/csa-iot.org\/wp-content\/uploads\/2022\/11\/22-27349-001_Matter-1.0-Core-Specification.pdf"},{"key":"7_CR6","unstructured":"Alliance, T.W.: WPA3 Specification v3.1 (2022). https:\/\/www.wi-fi.org\/system\/files\/WPA3%20Specification%20v3.1.pdf"},{"key":"7_CR7","unstructured":"Apple: Apple Platform Security (2022). https:\/\/help.apple.com\/pdf\/security\/en_US\/apple-platform-security-guide.pdf"},{"key":"7_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1007\/978-3-642-38980-1_8","volume-title":"Applied Cryptography and Network Security","author":"J-P Aumasson","year":"2013","unstructured":"Aumasson, J.-P., Neves, S., Wilcox-O\u2019Hearn, Z., Winnerlein, C.: BLAKE2: simpler, smaller, fast as MD5. In: Jacobson, M., Locasto, M., Mohassel, P., Safavi-Naini, R. (eds.) ACNS 2013. LNCS, vol. 7954, pp. 119\u2013135. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38980-1_8"},{"key":"7_CR9","unstructured":"Bai, S., et al.: CRYSTALS-Dilithium. https:\/\/pq-crystals.org\/dilithium\/data\/dilithium-specification-round3-20210208.pdf"},{"key":"7_CR10","unstructured":"Barak, B., Lindell, Y., Rabin, T.: Protocol initialization for the framework of universal composability. Cryptology ePrint Archive, Report 2004\/006 (2004). https:\/\/eprint.iacr.org\/2004\/006"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Barbosa, M., Gellert, K., Hesse, J., Jarecki, S.: Bare pake: universally composable key exchange from just passwords. Cryptology ePrint Archive, Paper 2024\/234 (2024). https:\/\/eprint.iacr.org\/2024\/234","DOI":"10.1007\/978-3-031-68379-4_6"},{"key":"7_CR12","doi-asserted-by":"publisher","unstructured":"Basso, A.: Poster: a post-quantum oblivious prf from isogenies. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201922, pp. 3327-3329. Association for Computing Machinery, New York (2022). https:\/\/doi.org\/10.1145\/3548606.3563542","DOI":"10.1145\/3548606.3563542"},{"key":"7_CR13","unstructured":"Basso, A.: A post-quantum round-optimal oblivious PRF from isogenies. Cryptology ePrint Archive, Report 2023\/225 (2023). https:\/\/eprint.iacr.org\/2023\/225"},{"key":"7_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"160","DOI":"10.1007\/978-3-030-92062-3_6","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"A Basso","year":"2021","unstructured":"Basso, A., Kutas, P., Merz, S.-P., Petit, C., Sanso, A.: Cryptanalysis of an oblivious PRF from supersingular isogenies. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13090, pp. 160\u2013184. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_6"},{"key":"7_CR15","doi-asserted-by":"publisher","first-page":"516","DOI":"10.1007\/978-3-031-33491-7_19","volume-title":"Applied Cryptography and Network Security","author":"H Beguinet","year":"2023","unstructured":"Beguinet, H., Chevalier, C., Pointcheval, D., Ricosset, T., Rossi, M.: Get a cake: generic transformations from key encaspulation mechanisms to password authenticated key exchanges. In: Tibouchi, M., Wang, X. (eds.) Applied Cryptography and Network Security, pp. 516\u2013538. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-33491-7_19"},{"key":"7_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-68697-5_1","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201996","author":"M Bellare","year":"1996","unstructured":"Bellare, M., Canetti, R., Krawczyk, H.: Keying hash functions for message authentication. In: Koblitz, N. (ed.) CRYPTO 1996. LNCS, vol. 1109, pp. 1\u201315. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68697-5_1"},{"key":"7_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1007\/3-540-45539-6_11","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2000","author":"M Bellare","year":"2000","unstructured":"Bellare, M., Pointcheval, D., Rogaway, P.: Authenticated key exchange secure against dictionary attacks. In: Preneel, B. (ed.) EUROCRYPT 2000. LNCS, vol. 1807, pp. 139\u2013155. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45539-6_11"},{"key":"7_CR18","doi-asserted-by":"publisher","unstructured":"Bellovin, S.M., Merritt, M.: Encrypted key exchange: password-based protocols secure against dictionary attacks. In: 1992 IEEE Symposium on Security and Privacy, pp. 72\u201384. IEEE Computer Society Press (1992). https:\/\/doi.org\/10.1109\/RISP.1992.213269","DOI":"10.1109\/RISP.1992.213269"},{"key":"7_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1007\/978-3-662-46447-2_21","volume-title":"Public-Key Cryptography \u2013 PKC 2015","author":"F Bergsma","year":"2015","unstructured":"Bergsma, F., Jager, T., Schwenk, J.: One-round key exchange with strong security: an efficient and generic construction in the standard model. In: Katz, J. (ed.) PKC 2015. LNCS, vol. 9020, pp. 477\u2013494. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46447-2_21"},{"key":"7_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"207","DOI":"10.1007\/11745853_14","volume-title":"Public Key Cryptography - PKC 2006","author":"DJ Bernstein","year":"2006","unstructured":"Bernstein, D.J.: Curve25519: new diffie-hellman speed records. In: Yung, M., Dodis, Y., Kiayias, A., Malkin, T. (eds.) PKC 2006. LNCS, vol. 3958, pp. 207\u2013228. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11745853_14"},{"key":"7_CR21","unstructured":"Bernstein, D.J.: The ChaCha family of stream ciphers (2008). https:\/\/cr.yp.to\/chacha.html"},{"issue":"2","key":"7_CR22","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/s13389-012-0027-1","volume":"2","author":"DJ Bernstein","year":"2012","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., Yang, B.Y.: High-speed high-security signatures. J. Cryptogr. Eng. 2(2), 77\u201389 (2012). https:\/\/doi.org\/10.1007\/s13389-012-0027-1","journal-title":"J. Cryptogr. Eng."},{"key":"7_CR23","doi-asserted-by":"publisher","unstructured":"Bertoni, G., Daemen, J., Hoffert, S., Peeters, M., Assche, G.V., Keer, R.V.: Farfalle: parallel permutation-based cryptography. IACR Trans. Symm. Cryptol. 2017(4), 1\u201338 (2017). https:\/\/doi.org\/10.13154\/tosc.v2017.i4.1-38","DOI":"10.13154\/tosc.v2017.i4.1-38"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Biryukov, A., Dinu, D., Khovratovich, D.: Argon2: the memory-hard function for password hashing and other applications (2015)","DOI":"10.1109\/EuroSP.2016.31"},{"key":"7_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"520","DOI":"10.1007\/978-3-030-64834-3_18","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"D Boneh","year":"2020","unstructured":"Boneh, D., Kogan, D., Woo, K.: Oblivious pseudorandom functions from isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12492, pp. 520\u2013550. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_18"},{"key":"7_CR26","doi-asserted-by":"publisher","unstructured":"Bos, J., et al.: Crystals - kyber: a CCA-secure module-lattice-based kem. In: 2018 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 353\u2013367 (2018). https:\/\/doi.org\/10.1109\/EuroSP.2018.00032","DOI":"10.1109\/EuroSP.2018.00032"},{"key":"7_CR27","doi-asserted-by":"publisher","unstructured":"Bos, J.W., Costello, C., Naehrig, M., Stebila, D.: Post-quantum key exchange for the TLS protocol from the ring learning with errors problem. In: 2015 IEEE Symposium on Security and Privacy, pp. 553\u2013570. IEEE Computer Society Press (2015). https:\/\/doi.org\/10.1109\/SP.2015.40","DOI":"10.1109\/SP.2015.40"},{"key":"7_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"451","DOI":"10.1007\/978-3-642-25516-8_27","volume-title":"Cryptography and Coding","author":"C Boyd","year":"2011","unstructured":"Boyd, C., Nieto, J.G.: On forward secrecy in one-round key exchange. In: Chen, L. (ed.) IMACC 2011. LNCS, vol. 7089, pp. 451\u2013468. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25516-8_27"},{"key":"7_CR29","doi-asserted-by":"publisher","unstructured":"Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. In: 42nd FOCS, pp. 136\u2013145. IEEE Computer Society Press (2001). https:\/\/doi.org\/10.1109\/SFCS.2001.959888","DOI":"10.1109\/SFCS.2001.959888"},{"key":"7_CR30","doi-asserted-by":"publisher","unstructured":"Canetti, R., Jain, P., Swanberg, M., Varia, M.: Universally composable end-to-end secure messaging. In: Dodis and Shrimpton [44], pp. 3\u201333. Springer, Heidelberg (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_1","DOI":"10.1007\/978-3-031-15979-4_1"},{"key":"7_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"453","DOI":"10.1007\/3-540-44987-6_28","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2001","author":"R Canetti","year":"2001","unstructured":"Canetti, R., Krawczyk, H.: Analysis of key-exchange protocols and their use for building secure channels. In: Pfitzmann, B. (ed.) EUROCRYPT 2001. LNCS, vol. 2045, pp. 453\u2013474. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44987-6_28"},{"key":"7_CR32","doi-asserted-by":"publisher","unstructured":"Canetti, R., Krawczyk, H.: Security analysis of IKE\u2019s signature-based key-exchange protocol. In: Yung, M. (ed.) CRYPTO\u00a02002. LNCS, vol.\u00a02442, pp. 143\u2013161. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45708-9_10. https:\/\/eprint.iacr.org\/2002\/120\/","DOI":"10.1007\/3-540-45708-9_10"},{"key":"7_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/3-540-46035-7_22","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 2002","author":"R Canetti","year":"2002","unstructured":"Canetti, R., Krawczyk, H.: Universally composable notions of key exchange and secure channels. In: Knudsen, L.R. (ed.) EUROCRYPT 2002. LNCS, vol. 2332, pp. 337\u2013351. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-46035-7_22"},{"key":"7_CR34","doi-asserted-by":"publisher","unstructured":"Canetti, R., Rabin, T.: Universal composition with joint state. In: Boneh [25], pp. 265\u2013281. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_16","DOI":"10.1007\/978-3-540-45146-4_16"},{"key":"7_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"395","DOI":"10.1007\/978-3-030-03332-3_15","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2018","author":"W Castryck","year":"2018","unstructured":"Castryck, W., Lange, T., Martindale, C., Panny, L., Renes, J.: CSIDH: an efficient post-quantum commutative group action. In: Peyrin, T., Galbraith, S. (eds.) ASIACRYPT 2018. LNCS, vol. 11274, pp. 395\u2013427. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03332-3_15"},{"issue":"3\u20134","key":"7_CR36","doi-asserted-by":"publisher","first-page":"251","DOI":"10.1504\/IJSN.2007.013178","volume":"2","author":"Z Cheng","year":"2007","unstructured":"Cheng, Z., Chen, L.: On security proof of mccullaghbarreto\u2019s key agreement protocol and its variants. Int. J. Secure. Network. 2(3\u20134), 251\u2013259 (2007). https:\/\/doi.org\/10.1504\/IJSN.2007.013178","journal-title":"Int. J. Secure. Network."},{"key":"7_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-75496-1_14","volume-title":"Information Security","author":"SSM Chow","year":"2007","unstructured":"Chow, S.S.M., Choo, K.-K.R.: Strongly-secure identity-based key agreement and anonymous extension. In: Garay, J.A., Lenstra, A.K., Mambo, M., Peralta, R. (eds.) ISC 2007. LNCS, vol. 4779, pp. 203\u2013220. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-75496-1_14"},{"key":"7_CR38","doi-asserted-by":"crossref","unstructured":"Cremers, C.: Examining indistinguishability-based security models for key exchange protocols: the case of CK, CK-HMQV, and eCK. In: Cheung, B.S.N., Hui, L.C.K., Sandhu, R.S., Wong, D.S. (eds.) ASIACCS 2011, pp. 80\u201391. ACM Press (2011)","DOI":"10.1145\/1966913.1966925"},{"key":"7_CR39","doi-asserted-by":"publisher","unstructured":"Cremers, C., Naor, M., Paz, S., Ronen, E.: CHIP and CRISP: protecting all parties against compromise through identity-binding PAKEs. In: Dodis and Shrimpton [44], pp. 668\u2013698. Springer, Heidelberg (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_23","DOI":"10.1007\/978-3-031-15979-4_23"},{"key":"7_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"282","DOI":"10.1007\/978-3-319-89339-6_16","volume-title":"Progress in Cryptology \u2013 AFRICACRYPT 2018","author":"J-P D\u2019Anvers","year":"2018","unstructured":"D\u2019Anvers, J.-P., Karmakar, A., Sinha Roy, S., Vercauteren, F.: Saber: module-LWR based key exchange, CPA-secure encryption and CCA-secure KEM. In: Joux, A., Nitaj, A., Rachidi, T. (eds.) AFRICACRYPT 2018. LNCS, vol. 10831, pp. 282\u2013305. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-89339-6_16"},{"key":"7_CR41","doi-asserted-by":"publisher","unstructured":"Davies, G.T., et al.: Security analysis of the WhatsApp end-to-end encrypted backup protocol. In: Handschuh and Lysyanskaya [56], pp. 330\u2013361. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_11","DOI":"10.1007\/978-3-031-38551-3_11"},{"key":"7_CR42","unstructured":"Dodgson, L.: Post-Quantum Building Blocks for Secure Computation - the Legendre OPRF (2023). https:\/\/ethz.ch\/content\/dam\/ethz\/special-interest\/infk\/inst-infsec\/appliedcrypto\/education\/theses\/Master_Thesis_Post_Quantum_Building_blocks_for_secure_computation.pdf"},{"key":"7_CR43","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1007\/978-3-031-44469-2_13","volume-title":"Progress in Cryptology - LATINCRYPT 2023","author":"S Faller","year":"2023","unstructured":"Faller, S., Ottenhues, A., Ottenhues, J.: Composable oblivious pseudo-random functions via garbled circuits. In: Aly, A., Tibouchi, M. (eds.) LATINCRYPT 2023. LNCS, vol. 14168, pp. 249\u2013270. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-44469-2_13"},{"key":"7_CR44","unstructured":"Fillion, R.: Secure Remote Password (SRP): How 1Password uses it (2018). https:\/\/blog.1password.com\/developers-how-we-use-srp-and-you-can-too\/. section: 1Password"},{"key":"7_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1007\/978-3-642-17499-5_3","volume-title":"Transactions on Computational Science X","author":"D Fiore","year":"2010","unstructured":"Fiore, D., Gennaro, R.: Identity-based key exchange protocols without pairings. In: Gavrilova, M.L., Tan, C.J.K., Moreno, E.D. (eds.) Transactions on Computational Science X. LNCS, vol. 6340, pp. 42\u201377. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-17499-5_3"},{"key":"7_CR46","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1007\/978-3-642-30057-8_28","volume-title":"Public Key Cryptography \u2013 PKC 2012","author":"A Fujioka","year":"2012","unstructured":"Fujioka, A., Suzuki, K., Xagawa, K., Yoneyama, K.: Strongly secure authenticated key exchange from factoring, codes, and lattices. In: Fischlin, M., Buchmann, J., Manulis, M. (eds.) PKC 2012. LNCS, vol. 7293, pp. 467\u2013484. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-30057-8_28"},{"key":"7_CR47","unstructured":"Gajland, P., de\u00a0Kock, B., Quaresma, M., Malavolta, G., Schwabe, P.: Swoosh: practical lattice-based non-interactive key exchange. Cryptology ePrint Archive, Report 2023\/271 (2023). https:\/\/eprint.iacr.org\/2023\/271"},{"key":"7_CR48","doi-asserted-by":"publisher","unstructured":"Gellert, K., Gj\u00f8steen, K., Jacobsen, H., Jager, T.: On optimal tightness for key exchange with full forward secrecy via key confirmation. In: Handschuh and Lysyanskaya [56], pp. 297\u2013329. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_10","DOI":"10.1007\/978-3-031-38551-3_10"},{"key":"7_CR49","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/11818175_9","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"C Gentry","year":"2006","unstructured":"Gentry, C., MacKenzie, P., Ramzan, Z.: A method for making password-based key exchange resilient to server compromise. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol. 4117, pp. 142\u2013159. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_9"},{"key":"7_CR50","doi-asserted-by":"publisher","unstructured":"Gong, L.: Lower bounds on messages and rounds for network authentication protocols. In: Denning, D.E., Pyle, R., Ganesan, R., Sandhu, R.S., Ashby, V. (eds.) ACM CCS 1993, pp. 26\u201337. ACM Press (1993). https:\/\/doi.org\/10.1145\/168588.168592","DOI":"10.1145\/168588.168592"},{"key":"7_CR51","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1007\/3-540-46885-4_5","volume-title":"Advances in Cryptology \u2014 EUROCRYPT \u201989","author":"CG G\u00fcnther","year":"1990","unstructured":"G\u00fcnther, C.G.: An identity-based key-exchange protocol. In: Quisquater, J.-J., Vandewalle, J. (eds.) EUROCRYPT 1989. LNCS, vol. 434, pp. 29\u201337. Springer, Heidelberg (1990). https:\/\/doi.org\/10.1007\/3-540-46885-4_5"},{"key":"7_CR52","doi-asserted-by":"publisher","unstructured":"Haase, B., Labrique, B.: AuCPace: efficient verifier-based PAKE protocol tailored for the IIoT. IACR TCHES 2019(2), 1\u201348 (2019). https:\/\/doi.org\/10.13154\/tches.v2019.i2.1-48. https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/7384","DOI":"10.13154\/tches.v2019.i2.1-48"},{"key":"7_CR53","unstructured":"Hamburg, M.: [curves] SPAKE2 and SPAKE2 Elligator Edition (2015). https:\/\/moderncrypto.org\/mail-archive\/curves\/2015\/000424.html"},{"key":"7_CR54","doi-asserted-by":"publisher","unstructured":"Harkins, D.: Simultaneous authentication of equals: a secure, password-based key exchange for mesh networks. In: 2008 Second International Conference on Sensor Technologies and Applications (sensorcomm 2008), pp. 839\u2013844 (2008). https:\/\/doi.org\/10.1109\/SENSORCOMM.2008.131","DOI":"10.1109\/SENSORCOMM.2008.131"},{"key":"7_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1007\/978-3-030-57990-6_29","volume-title":"Security and Cryptography for Networks","author":"J Hesse","year":"2020","unstructured":"Hesse, J.: Separating symmetric and asymmetric password-authenticated key exchange. In: Galdi, C., Kolesnikov, V. (eds.) SCN 2020. LNCS, vol. 12238, pp. 579\u2013599. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57990-6_29"},{"key":"7_CR56","doi-asserted-by":"publisher","unstructured":"Ishibashi, R., Yoneyama, K.: Compact password authenticated key exchange from group actions. In: Simpson, L., Baee, M.A.R. (eds.) ACISP 23. LNCS, vol. 13915, pp. 220\u2013247. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-35486-1_11","DOI":"10.1007\/978-3-031-35486-1_11"},{"key":"7_CR57","doi-asserted-by":"crossref","unstructured":"Jablon, D.P.: Extended password key exchange protocols immune to dictionary attacks. In: 6th IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE 1997), pp. 248\u2013255. IEEE Computer Society, Cambridge (1997)","DOI":"10.1109\/ENABL.1997.630822"},{"key":"7_CR58","doi-asserted-by":"publisher","unstructured":"Jaeger, J.: Let attackers program ideal models: modularity and composability for adaptive compromise. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0III. LNCS, vol. 14006, pp. 101\u2013131. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-30620-4_4","DOI":"10.1007\/978-3-031-30620-4_4"},{"key":"7_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-56784-2_1","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"J Jaeger","year":"2020","unstructured":"Jaeger, J., Tyagi, N.: Handling adaptive compromise for practical encryption schemes. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12170, pp. 3\u201332. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56784-2_1"},{"key":"7_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"456","DOI":"10.1007\/978-3-319-78372-7_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"S Jarecki","year":"2018","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10822, pp. 456\u2013486. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15"},{"key":"7_CR61","unstructured":"Katz, J., Rosenberg, M.: Latke: a framework for constructing identity-binding pakes. Cryptology ePrint Archive, Paper 2023\/324 (2023). https:\/\/eprint.iacr.org\/2023\/324"},{"key":"7_CR62","unstructured":"Kiltz, E., Neven, G.: Identity-Based Signatures (2009)"},{"key":"7_CR63","doi-asserted-by":"publisher","unstructured":"Krawczyk, H.: SIGMA: The \u201cSIGn-and-MAc\u201d approach to authenticated Diffie-Hellman and its use in the IKE protocols. In: Boneh [25], pp. 400\u2013425. Springer, Heidelberg. https:\/\/doi.org\/10.1007\/978-3-540-45146-4_24","DOI":"10.1007\/978-3-540-45146-4_24"},{"key":"7_CR64","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"546","DOI":"10.1007\/11535218_33","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"H Krawczyk","year":"2005","unstructured":"Krawczyk, H.: HMQV: a high-performance secure Diffie-Hellman protocol. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol. 3621, pp. 546\u2013566. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11535218_33"},{"key":"7_CR65","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"631","DOI":"10.1007\/978-3-642-14623-7_34","volume-title":"Advances in Cryptology \u2013 CRYPTO 2010","author":"H Krawczyk","year":"2010","unstructured":"Krawczyk, H.: Cryptographic extraction and key derivation: the HKDF scheme. In: Rabin, T. (ed.) CRYPTO 2010. LNCS, vol. 6223, pp. 631\u2013648. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-14623-7_34"},{"key":"7_CR66","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-75670-5_1","volume-title":"ProvSec 2007","author":"BA LaMacchia","year":"2007","unstructured":"LaMacchia, B.A., Lauter, K., Mityagin, A.: Stronger security of authenticated key exchange. In: Susilo, W., Liu, J.K., Mu, Y. (eds.) ProvSec 2007. LNCS, vol. 4784, pp. 1\u201316. Springer, Heidelberg (Nov (2007). https:\/\/doi.org\/10.1007\/978-3-540-75670-5_1"},{"key":"7_CR67","doi-asserted-by":"publisher","unstructured":"Liu, X., Liu, S., Han, S., Gu, D.: EKE meets tight security in the Universally Composable framework. In: Boldyreva, A., Kolesnikov, V. (eds.) PKC\u00a02023, Part\u00a0I. LNCS, vol. 13940, pp. 685\u2013713. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-31368-4_24","DOI":"10.1007\/978-3-031-31368-4_24"},{"key":"7_CR68","doi-asserted-by":"publisher","unstructured":"Lounis, K.: Cut it: deauthentication attack on bluetooth. In: 2021 14th International Conference on Security of Information and Networks (SIN), vol.\u00a01, pp.\u00a01\u20138 (2021). https:\/\/doi.org\/10.1109\/SIN54109.2021.9699265","DOI":"10.1109\/SIN54109.2021.9699265"},{"key":"7_CR69","doi-asserted-by":"publisher","unstructured":"Lyubashevsky, V., Seiler, G.: NTTRU: truly fast NTRU using NTT. IACR TCHES 2019(3), 180\u2013201 (2019). https:\/\/doi.org\/10.13154\/tches.v2019.i3.180-201. https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/8293","DOI":"10.13154\/tches.v2019.i3.180-201"},{"key":"7_CR70","unstructured":"Marlinspike, M.: The Double Ratchet Algorithm (2016). https:\/\/signal.org\/docs\/specifications\/doubleratchet\/"},{"key":"7_CR71","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1007\/3-540-48184-2_15","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201987","author":"E Okamoto","year":"1988","unstructured":"Okamoto, E.: Key distribution systems based on identification information. In: Pomerance, C. (ed.) CRYPTO 1987. LNCS, vol. 293, pp. 194\u2013202. Springer, Heidelberg (1988). https:\/\/doi.org\/10.1007\/3-540-48184-2_15"},{"key":"7_CR72","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"197","DOI":"10.1007\/978-3-319-11659-4_12","volume-title":"Post-Quantum Cryptography","author":"C Peikert","year":"2014","unstructured":"Peikert, C.: Lattice cryptography for the internet. In: Mosca, M. (ed.) PQCrypto 2014. LNCS, vol. 8772, pp. 197\u2013219. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-11659-4_12"},{"key":"7_CR73","unstructured":"Schepers, D., Ranganathan, A., Vanhoef, M.: Framing frames: bypassing Wi-Fi encryption by manipulating transmit queues. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 53\u201368. USENIX Association, Anaheim (2023). https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/schepers"},{"key":"7_CR74","doi-asserted-by":"crossref","unstructured":"Shim, K.: Efficient id-based authenticated key agreement protocol based on weil pairing. Electron. Lett. 39, 653\u2013654(1) (2003). https:\/\/digital-library.theiet.org\/content\/journals\/10.1049\/el_20030448","DOI":"10.1049\/el:20030448"},{"key":"7_CR75","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/978-3-030-64381-2_2","volume-title":"Theory of Cryptography","author":"V Shoup","year":"2020","unstructured":"Shoup, V.: Security analysis of SPAKE2+. In: Pass, R., Pietrzak, K. (eds.) Theory of Cryptography. LNCS, vol. 12552, pp. 31\u201360. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64381-2_2"},{"key":"7_CR76","unstructured":"Shue, C.A., Paul, N., Taylor, C.R.: From an IP address to a street address: using wireless signals to locate a target. In: 7th USENIX Workshop on Offensive Technologies (WOOT 13). USENIX Association, Washington, D.C. (2013). https:\/\/www.usenix.org\/conference\/woot13\/workshop-program\/presentation\/shue"},{"key":"7_CR77","unstructured":"Thomas, S.: BSCRYPT: a cache hard password hash (2022). https:\/\/tobtu.com\/files\/bsideslv2022.pdf"},{"key":"7_CR78","unstructured":". Thomas, S.: Demystifying key stretching and PAKEs (2022). https:\/\/www.blackhat.com\/us-22\/briefings\/schedule\/#demystifying-key-stretching-and-pakes-27615, black Hat 2022"},{"key":"7_CR79","unstructured":"Thread Group: Thread commissioning (2015). https:\/\/www.threadgroup.org\/Portals\/0\/documents\/support\/CommissioningWhitePaper_658_2.pdf"},{"key":"7_CR80","unstructured":"Valence, H.D., Grigg, J., Hamburg, M., Lovecruft, I., Tankersley, G., Valsorda, F.: The ristretto255 and decaf448 Groups. Request for Comments RFC 9496, Internet Engineering Task Force (2023). https:\/\/datatracker.ietf.org\/doc\/rfc9496"},{"key":"7_CR81","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/978-3-642-35840-1_9","volume-title":"Transactions on Computational Science XVII","author":"Y Wang","year":"2013","unstructured":"Wang, Y.: Efficient identity-based and authenticated key agreement protocol. In: Gavrilova, M.L., Tan, C.J.K. (eds.) Transactions on Computational Science XVII. LNCS, vol. 7420, pp. 172\u2013197. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-35840-1_9"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-68379-4_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T00:03:35Z","timestamp":1786752215000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-68379-4_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031683787","9783031683794"],"references-count":81,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-68379-4_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"16 August 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 August 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}