{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:10:31Z","timestamp":1785831031625,"version":"3.56.0"},"publisher-location":"Cham","reference-count":55,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031911231","type":"print"},{"value":"9783031911248","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-91124-8_14","type":"book-chapter","created":{"date-parts":[[2025,4,27]],"date-time":"2025-04-27T09:22:58Z","timestamp":1745745778000},"page":"395-420","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["PAKE Combiners and\u00a0Efficient Post-quantum Instantiations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2875-6198","authenticated-orcid":false,"given":"Julia","family":"Hesse","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9784-125X","authenticated-orcid":false,"given":"Michael","family":"Rosenberg","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,28]]},"reference":[{"key":"14_CR1","unstructured":"Deployments of fancy cryptography (2024). https:\/\/github.com\/fancy-cryptography\/fancy-cryptography"},{"key":"14_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1007\/978-3-030-56784-2_10","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"M Abdalla","year":"2020","unstructured":"Abdalla, M., Barbosa, M., Bradley, T., Jarecki, S., Katz, J., Xu, J.: Universally composable relaxed password authenticated key exchange. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12170, pp. 278\u2013307. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56784-2_10"},{"key":"14_CR3","doi-asserted-by":"publisher","unstructured":"Abdalla, M., Eisenhofer, T., Kiltz, E., Kunzweiler, S., Riepel, D.: Password-authenticated key exchange from group actions. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0II. LNCS, vol. 13508, pp. 699\u2013728. Springer, Heidelberg (2022). https:\/\/doi.org\/10.1007\/978-3-031-15979-4_24","DOI":"10.1007\/978-3-031-15979-4_24"},{"key":"14_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1007\/978-3-030-92068-5_24","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2021","author":"M Abdalla","year":"2021","unstructured":"Abdalla, M., Haase, B., Hesse, J.: Security analysis of\u00a0CPace. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT 2021. LNCS, vol. 13093, pp. 711\u2013741. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92068-5_24"},{"key":"14_CR5","unstructured":"Abdalla, M., Haase, B., Hesse, J.: CPace, a balanced composable PAKE. Internet Draft draft-irtf-cfrg-cpace-13, Internet engineering task force (2024). https:\/\/datatracker.ietf.org\/doc\/draft-irtf-cfrg-cpace-13, pp. 96"},{"key":"14_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"191","DOI":"10.1007\/978-3-540-30574-3_14","volume-title":"Topics in Cryptology \u2013 CT-RSA 2005","author":"M Abdalla","year":"2005","unstructured":"Abdalla, M., Pointcheval, D.: Simple password-based encrypted key exchange protocols. In: Menezes, A. (ed.) CT-RSA 2005. LNCS, vol. 3376, pp. 191\u2013208. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30574-3_14"},{"key":"14_CR7","unstructured":"Adrian, D., Beck, B., Benjamin, D., O\u2019Brien, D.: Advancing our amazing bet on asymmetric cryptography (2024). https:\/\/blog.chromium.org\/2024\/05\/advancing-our-amazing-bet-on-asymmetric.html"},{"key":"14_CR8","unstructured":"Alnahawi, N., Alperin-Sheriff, J., Apon, D., Wiesmaier, A.: NICE-PAKE: on the security of KEM-based PAKE constructions without ideal ciphers. Cryptology ePrint Archive, Paper 2024\/1957 (2024). https:\/\/eprint.iacr.org\/2024\/1957"},{"key":"14_CR9","unstructured":"Arriaga, A., Barbosa, M., Jarecki, S.: NoIC: PAKE from KEM without ideal ciphers. Cryptology ePrint Archive, Paper 2025\/231 (2025). https:\/\/eprint.iacr.org\/2025\/231"},{"key":"14_CR10","unstructured":"Arriaga, A., Barbosa, M., Jarecki, S., Skrobot, M.: C\u2019est tr\u00e8s chic: a compact password-authenticated key exchange from lattice-based KEM. Cryptology ePrint Archive, Paper 2024\/308 (2024). https:\/\/eprint.iacr.org\/2024\/308, https:\/\/eprint.iacr.org\/2024\/308"},{"key":"14_CR11","doi-asserted-by":"publisher","unstructured":"Barbosa, M., et al.: X-wing. IACR Commun. Cryptol. 1(1) (2024). https:\/\/doi.org\/10.62056\/a3qj89n4e","DOI":"10.62056\/a3qj89n4e"},{"key":"14_CR12","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1007\/978-3-031-68379-4_6","volume-title":"Advances in Cryptology - CRYPTO 2024","author":"M Barbosa","year":"2024","unstructured":"Barbosa, M., Gellert, K., Hesse, J., Jarecki, S.: Bare PAKE: universally composable key exchange from just passwords. In: Reyzin, L., Stebila, D. (eds.) Advances in Cryptology - CRYPTO 2024, pp. 183\u2013217. Springer Nature Switzerland, Cham (2024)"},{"key":"14_CR13","doi-asserted-by":"publisher","unstructured":"Beguinet, H., Chevalier, C., Pointcheval, D., Ricosset, T., Rossi, M.: GeT a CAKE: generic transformations from key encaspulation mechanisms to password authenticated key exchanges. In: Tibouchi, M., Wang, X. (eds.) ACNS 23, Part\u00a0II. LNCS, vol. 13906, pp. 516\u2013538. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-33491-7_19","DOI":"10.1007\/978-3-031-33491-7_19"},{"key":"14_CR14","doi-asserted-by":"publisher","unstructured":"Bellovin, S., Merritt, M.: Encrypted key exchange: password-based protocols secure against dictionary attacks. In: Proceedings 1992 IEEE Computer Society Symposium on Research in Security and Privacy, pp. 72\u201384 (1992). https:\/\/doi.org\/10.1109\/RISP.1992.213269","DOI":"10.1109\/RISP.1992.213269"},{"key":"14_CR15","unstructured":"Bernstein, D.J., et al.: KyberSlash: exploiting secret-dependent division timings in Kyber implementations. Cryptology ePrint Archive, Paper 2024\/1049 (2024). https:\/\/eprint.iacr.org\/2024\/1049"},{"key":"14_CR16","doi-asserted-by":"publisher","unstructured":"Bernstein, D.J., Hamburg, M., Krasnova, A., Lange, T.: Elligator: elliptic-curve points indistinguishable from uniform random strings. In: Sadeghi, A.R., Gligor, V.D., Yung, M. (eds.) ACM CCS 2013, pp. 967\u2013980. ACM Press (2013). https:\/\/doi.org\/10.1145\/2508859.2516734","DOI":"10.1145\/2508859.2516734"},{"key":"14_CR17","unstructured":"Bindel, N., Hale, B.: A note on hybrid signature schemes. Cryptology ePrint Archive, Paper 2023\/423 (2023).https:\/\/eprint.iacr.org\/2023\/423, https:\/\/eprint.iacr.org\/2023\/423"},{"key":"14_CR18","doi-asserted-by":"publisher","unstructured":"Bos, J.W., et al.: Frodo: Take off the ring! Practical, quantum-secure key exchange from LWE. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) ACM CCS 2016, pp. 1006\u20131018. ACM Press (2016). https:\/\/doi.org\/10.1145\/2976749.2978425","DOI":"10.1145\/2976749.2978425"},{"key":"14_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"442","DOI":"10.1007\/978-3-030-21568-2_22","volume-title":"Applied Cryptography and Network Security","author":"T Bradley","year":"2019","unstructured":"Bradley, T., Camenisch, J., Jarecki, S., Lehmann, A., Neven, G., Xu, J.: Password-Authenticated public-key encryption. In: Deng, R.H., Gauthier-Uma\u00f1a, V., Ochoa, M., Yung, M. (eds.) ACNS 2019. LNCS, vol. 11464, pp. 442\u2013462. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-21568-2_22"},{"key":"14_CR20","doi-asserted-by":"publisher","unstructured":"Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. In: 42nd FOCS, pp. 136\u2013145. IEEE Computer Society Press (2001). https:\/\/doi.org\/10.1109\/SFCS.2001.959888","DOI":"10.1109\/SFCS.2001.959888"},{"key":"14_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"404","DOI":"10.1007\/11426639_24","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"R Canetti","year":"2005","unstructured":"Canetti, R., Halevi, S., Katz, J., Lindell, Y., MacKenzie, P.: Universally composable password-based key exchange. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 404\u2013421. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_24"},{"key":"14_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/978-3-540-45146-4_16","volume-title":"Advances in Cryptology - CRYPTO 2003","author":"R Canetti","year":"2003","unstructured":"Canetti, R., Rabin, T.: Universal composition with joint state. In: Boneh, D. (ed.) CRYPTO 2003. LNCS, vol. 2729, pp. 265\u2013281. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45146-4_16"},{"key":"14_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1007\/978-3-319-52153-4_11","volume-title":"Topics in Cryptology \u2013 CT-RSA 2017","author":"J Ding","year":"2017","unstructured":"Ding, J., Alsayigh, S., Lancrenon, J., RV, S., Snook, M.: Provably secure password authenticated key exchange based on RLWE for the post-quantum world. In: Handschuh, H. (ed.) CT-RSA 2017. LNCS, vol. 10159, pp. 183\u2013204. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-52153-4_11"},{"key":"14_CR24","unstructured":"Facebook: The labyrinth encrypted message storage protocol (2023). https:\/\/engineering.fb.com\/wp-content\/uploads\/2023\/12\/TheLabyrinthEncryptedMessageStorageProtocol_12-6-2023.pdf"},{"key":"14_CR25","unstructured":"French cybersecurity agency: ANSSI views on the post-quantum cryptography transition (2022). https:\/\/cyber.gouv.fr\/sites\/default\/files\/document\/EN_Position.pdf"},{"key":"14_CR26","unstructured":"Gajland, P., de\u00a0Kock, B., Quaresma, M., Malavolta, G., Schwabe, P.: SWOOSH: efficient lattice-based non-interactive key exchange. In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 487\u2013504. USENIX Association, Philadelphia, PA (2024). https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/gajland"},{"key":"14_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"142","DOI":"10.1007\/11818175_9","volume-title":"Advances in Cryptology - CRYPTO 2006","author":"C Gentry","year":"2006","unstructured":"Gentry, C., MacKenzie, P., Ramzan, Z.: A method for making password-based key exchange resilient to server compromise. In: Dwork, C. (ed.) CRYPTO 2006. LNCS, vol. 4117, pp. 142\u2013159. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_9"},{"key":"14_CR28","unstructured":"German federal office for information security: BSI TR-02102-1, cryptographic mechanisms: recommendations and key lengths (2024). version 2024-01, https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/EN\/BSI\/Publications\/TechGuidelines\/TG02102\/BSI-TR-02102-1.pdf"},{"key":"14_CR29","doi-asserted-by":"publisher","unstructured":"Gong, L.: Lower bounds on messages and rounds for network authentication protocols. In: Denning, D.E., Pyle, R., Ganesan, R., Sandhu, R.S., Ashby, V. (eds.) ACM CCS 93, pp. 26\u201337. ACM Press (1993). https:\/\/doi.org\/10.1145\/168588.168592","DOI":"10.1145\/168588.168592"},{"key":"14_CR30","doi-asserted-by":"publisher","unstructured":"Guo, Q., Hlauschek, C., Johansson, T., Lahr, N., Nilsson, A., Schr\u00f6der, R.L.: Don\u2019t reject this: key-recovery timing attacks due to rejection-sampling in HQC and BIKE. IACR TCHES 2022(3), 223\u2013263 (2022). https:\/\/doi.org\/10.46586\/tches.v2022.i3.223-263","DOI":"10.46586\/tches.v2022.i3.223-263"},{"key":"14_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/978-3-030-56880-1_13","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"Q Guo","year":"2020","unstructured":"Guo, Q., Johansson, T., Nilsson, A.: A Key-recovery timing attack on post-quantum primitives using the fujisaki-okamoto transformation and its application on FrodoKEM. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12171, pp. 359\u2013386. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56880-1_13"},{"key":"14_CR32","doi-asserted-by":"publisher","unstructured":"Haase, B., Labrique, B.: AuCPace: efficient verifier-based PAKE protocol tailored for the IIoT. IACR TCHES 2019(2), 1\u201348 (2019). https:\/\/doi.org\/10.13154\/tches.v2019.i2.1-48, https:\/\/tches.iacr.org\/index.php\/TCHES\/article\/view\/7384","DOI":"10.13154\/tches.v2019.i2.1-48"},{"issue":"4","key":"14_CR33","doi-asserted-by":"publisher","first-page":"1364","DOI":"10.1137\/S0097539793244708","volume":"28","author":"J H\u00e5stad","year":"1999","unstructured":"H\u00e5stad, J., Impagliazzo, R., Levin, L.A., Luby, M.: A pseudorandom generator from any one-way function. SIAM J. Comput. 28(4), 1364\u20131396 (1999)","journal-title":"SIAM J. Comput."},{"key":"14_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"579","DOI":"10.1007\/978-3-030-57990-6_29","volume-title":"Security and Cryptography for Networks","author":"J Hesse","year":"2020","unstructured":"Hesse, J.: Separating symmetric and asymmetric password-authenticated key exchange. In: Galdi, C., Kolesnikov, V. (eds.) SCN 2020. LNCS, vol. 12238, pp. 579\u2013599. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-57990-6_29"},{"key":"14_CR35","unstructured":"Hesse, J., Rosenberg, M.: PAKE combiners and efficient post-quantum instantiations. Cryptology ePrint Archive, Paper 2024\/1621 (2024). https:\/\/eprint.iacr.org\/2024\/1621"},{"key":"14_CR36","doi-asserted-by":"publisher","unstructured":"Huang, S., Sim, R.Q., Chuengsatiansup, C., Guo, Q., Johansson, T.: Cache-timing attack against HQC. IACR TCHES 2023(3), 136\u2013163 (2023). https:\/\/doi.org\/10.46586\/tches.v2023.i3.136-163","DOI":"10.46586\/tches.v2023.i3.136-163"},{"key":"14_CR37","doi-asserted-by":"publisher","unstructured":"Ishibashi, R., Yoneyama, K.: Compact password authenticated key exchange from group actions. In: Simpson, L., Baee, M.A.R. (eds.) ACISP 23. LNCS, vol. 13915, pp. 220\u2013247. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-35486-1_11","DOI":"10.1007\/978-3-031-35486-1_11"},{"key":"14_CR38","unstructured":"Januzelli, J., Roy, L., Xu, J.: Under what conditions is encrypted key exchange actually secure? Cryptology ePrint Archive, Paper 2024\/324 (2024). https:\/\/eprint.iacr.org\/2024\/324"},{"key":"14_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"456","DOI":"10.1007\/978-3-319-78372-7_15","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"S Jarecki","year":"2018","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018. LNCS, vol. 10822, pp. 456\u2013486. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15"},{"key":"14_CR40","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1007\/978-3-031-68379-4","volume-title":"Advances in Cryptology - CRYPTO 2024","author":"J Katz","year":"2024","unstructured":"Katz, J., Rosenberg, M.: LATKE: a framework for constructing identity-binding PAKEs. In: Reyzin, L., Stebila, D. (eds.) Advances in Cryptology - CRYPTO 2024, pp. 218\u2013250. Springer Nature Switzerland, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-68379-4"},{"key":"14_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-642-19571-6_18","volume-title":"Theory of Cryptography","author":"J Katz","year":"2011","unstructured":"Katz, J., Vaikuntanathan, V.: Round-optimal password-based authenticated key exchange. In: Ishai, Y. (ed.) TCC 2011. LNCS, vol. 6597, pp. 293\u2013310. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19571-6_18"},{"key":"14_CR42","doi-asserted-by":"publisher","unstructured":"Ladd, W.: SPAKE2, a password-authenticated key exchange. Request for comments RFC 9382, internet engineering task force (2023). https:\/\/doi.org\/10.17487\/RFC9382, https:\/\/datatracker.ietf.org\/doc\/rfc9382, pp. 17","DOI":"10.17487\/RFC9382"},{"key":"14_CR43","doi-asserted-by":"publisher","unstructured":"Langley, A., Hamburg, M., Turner, S.: Elliptic Curves for Security. RFC 7748 (Informational) (2016). https:\/\/doi.org\/10.17487\/RFC7748, https:\/\/www.rfc-editor.org\/rfc\/rfc7748.txt","DOI":"10.17487\/RFC7748"},{"key":"14_CR44","doi-asserted-by":"publisher","unstructured":"Lindner, R., Peikert, C.: Better key sizes (and attacks) for LWE-based encryption. In: Kiayias, A. (ed.) CT-RSA\u00a02011. LNCS, vol.\u00a06558, pp. 319\u2013339. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19074-2_21","DOI":"10.1007\/978-3-642-19074-2_21"},{"key":"14_CR45","unstructured":"Lyu, Y., Liu, S.: Hybrid password authentication key exchange in the UC framework. Cryptology ePrint Archive, Paper 2024\/1630 (2024). https:\/\/eprint.iacr.org\/2024\/1630"},{"key":"14_CR46","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1007\/978-3-031-58754-2_5","volume-title":"Advances in Cryptology - EUROCRYPT 2024","author":"Y Lyu","year":"2024","unstructured":"Lyu, Y., Liu, S., Han, S.: Universal composable password authenticated key exchange for the post-quantum world. In: Joye, M., Leander, G. (eds.) Advances in Cryptology - EUROCRYPT 2024, pp. 120\u2013150. Springer Nature Switzerland, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58754-2_5"},{"key":"14_CR47","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/978-981-96-0935-2_2","volume-title":"Advances in Cryptology - ASIACRYPT 2024","author":"Y Lyu","year":"2025","unstructured":"Lyu, Y., Liu, S., Han, S.: Efficient asymmetric PAKE compiler from KEM and AE. In: Chung, K.M., Sasaki, Y. (eds.) Advances in Cryptology - ASIACRYPT 2024, pp. 34\u201365. Springer Nature Singapore, Singapore (2025). https:\/\/doi.org\/10.1007\/978-981-96-0935-2_2"},{"key":"14_CR48","doi-asserted-by":"publisher","unstructured":"McQuoid, I., Rosulek, M., Roy, L.: Minimal symmetric PAKE and 1-out-of-N OT from programmable-once public functions. In: Ligatti, J., Ou, X., Katz, J., Vigna, G. (eds.) ACM CCS 2020, pp. 425\u2013442. ACM Press (2020). https:\/\/doi.org\/10.1145\/3372297.3417870","DOI":"10.1145\/3372297.3417870"},{"key":"14_CR49","doi-asserted-by":"publisher","unstructured":"Pan, J., Zeng, R.: A generic construction of tightly secure password-based authenticated key exchange. In: Guo, J., Steinfeld, R. (eds.) ASIACRYPT\u00a02023, Part\u00a0VIII. LNCS, vol. 14445, pp. 143\u2013175. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-981-99-8742-9_5","DOI":"10.1007\/978-981-99-8742-9_5"},{"key":"14_CR50","doi-asserted-by":"crossref","unstructured":"Pointcheval, D., Wang, G.: VTBPEKE: verifier-based two-basis password exponential key exchange. In: Karri, R., Sinanoglu, O., Sadeghi, A.R., Yi, X. (eds.) ASIACCS 17, pp. 301\u2013312. ACM Press (2017)","DOI":"10.1145\/3052973.3053026"},{"key":"14_CR51","doi-asserted-by":"publisher","unstructured":"Regev, O.: On lattices, learning with errors, random linear codes, and cryptography. In: Gabow, H.N., Fagin, R. (eds.) 37th ACM STOC, pp. 84\u201393. ACM Press (2005). https:\/\/doi.org\/10.1145\/1060590.1060603","DOI":"10.1145\/1060590.1060603"},{"key":"14_CR52","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-031-08896-4_7","volume-title":"Information Security and Cryptology - ICISC 2021","author":"P Ren","year":"2022","unstructured":"Ren, P., Gu, X.: Practical post-quantum password-authenticated key exchange based-on module-lattice. In: Park, J.H., Seo, S.H. (eds.) Information Security and Cryptology - ICISC 2021, pp. 137\u2013156. Springer International Publishing, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-08896-4_7"},{"key":"14_CR53","doi-asserted-by":"publisher","unstructured":"Santos, B.F.D., Gu, Y., Jarecki, S.: Randomized half-ideal cipher on groups with applications to UC (a)PAKE. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 128\u2013156. Springer, Heidelberg (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_5","DOI":"10.1007\/978-3-031-30589-4_5"},{"key":"14_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/978-3-030-64381-2_2","volume-title":"Theory of Cryptography","author":"V Shoup","year":"2020","unstructured":"Shoup, V.: Security analysis of $$\\mathit{SPAKE2}+$$. In: Pass, R., Pietrzak, K. (eds.) TCC 2020. LNCS, vol. 12552, pp. 31\u201360. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64381-2_2"},{"key":"14_CR55","unstructured":"Westerbaan, B.: The state of the post-quantum Internet (2024). https:\/\/blog.cloudflare.com\/pq-2024, the Cloudflare Blog"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-91124-8_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,27]],"date-time":"2025-04-27T09:23:12Z","timestamp":1745745792000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-91124-8_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031911231","9783031911248"],"references-count":55,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-91124-8_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"28 April 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Madrid","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 May 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 May 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}