{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:35:26Z","timestamp":1785605726459,"version":"3.56.0"},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2022,9,27]],"date-time":"2022-09-27T00:00:00Z","timestamp":1664236800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,9,27]],"date-time":"2022-09-27T00:00:00Z","timestamp":1664236800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"NTNU Norwegian University of Science and Technology"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cryptol"],"published-print":{"date-parts":[[2022,10]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>We propose the <jats:italic>first<\/jats:italic> tight security proof for the ordinary two-message signed Diffie\u2013Hellman key exchange protocol in the random oracle model. Our proof is based on the strong computational Diffie\u2013Hellman assumption and the multiuser security of a digital signature scheme. With our security proof, the signed DH protocol can be deployed with optimal parameters, independent of the number of users or sessions, without the need to compensate any security loss. We abstract our approach with a new notion called verifiable key exchange. In contrast to a known tight three-message variant of the signed Diffie\u2013Hellman protocol (Gj\u00f8steen and Jager, in: Shacham, Boldyreva (eds) CRYPTO\u00a02018, Part\u00a0II. LNCS, Springer, Heidelberg, 2018), we do not require any modification to the original protocol, and our tightness result is proven in the \u201cSingle-Bit-Guess\u201d model which we know can be tightly composed with symmetric cryptographic primitives to establish a secure channel. Finally, we extend our approach to the group setting and construct the <jats:italic>first<\/jats:italic> tightly secure group authenticated key exchange protocol.<\/jats:p>","DOI":"10.1007\/s00145-022-09438-y","type":"journal-article","created":{"date-parts":[[2022,9,27]],"date-time":"2022-09-27T20:19:36Z","timestamp":1664309976000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Signed (Group) Diffie\u2013Hellman Key Exchange with Tight Security"],"prefix":"10.1007","volume":"35","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7459-6850","authenticated-orcid":false,"given":"Jiaxin","family":"Pan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4429-7267","authenticated-orcid":false,"given":"Chen","family":"Qian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1276-3350","authenticated-orcid":false,"given":"Magnus","family":"Ringerud","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,27]]},"reference":[{"key":"9438_CR1","doi-asserted-by":"crossref","unstructured":"M. Abdalla, M. Bellare, P. Rogaway, The oracle Diffie-Hellman assumptions and an analysis of DHIES, in Naccache, D. (ed.) CT-RSA\u00a02001. LNCS, vol. 2020 (Springer, Heidelberg, 2001), pp. 143\u2013158","DOI":"10.1007\/3-540-45353-9_12"},{"key":"9438_CR2","doi-asserted-by":"crossref","unstructured":"C. Bader, D. Hofheinz, T. Jager, E. Kiltz, Y. Li, Tightly-secure authenticated key exchange, in Dodis, Y., Nielsen, J.B. (eds.) TCC\u00a02015, Part\u00a0I. LNCS, vol. 9014 (Springer, Heidelberg, 2015), pp. 629\u2013658","DOI":"10.1007\/978-3-662-46494-6_26"},{"key":"9438_CR3","doi-asserted-by":"crossref","unstructured":"M. Bellare, W. Dai, The multi-base discrete logarithm problem: Tight reductions and non-rewinding proofs for Schnorr identification and signatures, in Bhargavan, K., Oswald, E., Prabhakaran, M. (eds.) INDOCRYPT\u00a02020. LNCS, vol. 12578 (Springer, Heidelberg, 2020), pp. 529\u2013552","DOI":"10.1007\/978-3-030-65277-7_24"},{"key":"9438_CR4","doi-asserted-by":"crossref","unstructured":"M. Bellare, P. Rogaway, Random oracles are practical: A paradigm for designing efficient protocols, in Denning, D.E., Pyle, R., Ganesan, R., Sandhu, R.S., Ashby, V. (eds.) ACM CCS 93 (ACM Press, 1993), pp. 62\u201373","DOI":"10.1145\/168588.168596"},{"key":"9438_CR5","doi-asserted-by":"crossref","unstructured":"M. Bellare, P. Rogaway, Entity authentication and key distribution, in Stinson, D.R. (ed.) CRYPTO\u201993. LNCS, vol. 773 (Springer, Heidelberg, 1994), pp. 232\u2013249","DOI":"10.1007\/3-540-48329-2_21"},{"key":"9438_CR6","doi-asserted-by":"crossref","unstructured":"M. Bellare, P. Rogaway, The security of triple encryption and a framework for code-based game-playing proofs, in Vaudenay, S. (ed.) EUROCRYPT\u00a02006. LNCS, vol. 4004 (Springer, Heidelberg, 2006), pp. 409\u2013426","DOI":"10.1007\/11761679_25"},{"key":"9438_CR7","doi-asserted-by":"crossref","unstructured":"F. Bergsma, T. Jager, J. Schwenk, One-round key exchange with strong security: An efficient and generic construction in the standard model, in Katz, J. (ed.) PKC\u00a02015. LNCS, vol. 9020 (Springer, Heidelberg, 2015), pp. 477\u2013494","DOI":"10.1007\/978-3-662-46447-2_21"},{"key":"9438_CR8","doi-asserted-by":"crossref","unstructured":"D.J. Bernstein, N. Duif, T. Lange, P. Schwabe, B.Y. Yang, High-speed high-security signatures, in Preneel, B., Takagi, T. (eds.) CHES\u00a02011. LNCS, vol. 6917 (Springer, Heidelberg, 2011), pp. 124\u2013142","DOI":"10.1007\/978-3-642-23951-9_9"},{"key":"9438_CR9","doi-asserted-by":"crossref","unstructured":"E. Bresson, O. Chevassut, D. Pointcheval, Provably authenticated group Diffie-Hellman key exchange\u2014the dynamic case, in: Boyd, C. (ed.) ASIACRYPT\u00a02001. LNCS, vol. 2248 (Springer, Heidelberg, 2001), pp. 290\u2013309","DOI":"10.1007\/3-540-45682-1_18"},{"key":"9438_CR10","doi-asserted-by":"crossref","unstructured":"E. Bresson, O. Chevassut, D. Pointcheval, Dynamic group Diffie-Hellman key exchange under standard assumptions, in Knudsen, L.R. (ed.) EUROCRYPT\u00a02002. LNCS, vol. 2332 (Springer, Heidelberg, 2002), pp. 321\u2013336","DOI":"10.1007\/3-540-46035-7_21"},{"key":"9438_CR11","doi-asserted-by":"crossref","unstructured":"E. Bresson, O. Chevassut, D. Pointcheval, J.J. Quisquater, Provably authenticated group Diffie-Hellman key exchange, in Reiter, M.K., Samarati, P. (eds.) ACM CCS 2001 (ACM Press, 2001), pp. 255\u2013264","DOI":"10.1007\/3-540-45682-1_18"},{"key":"9438_CR12","doi-asserted-by":"crossref","unstructured":"M. Burmester, Y. Desmedt, A secure and efficient conference key distribution system (extended abstract), in: Santis, A.D. (ed.) EUROCRYPT\u201994. LNCS, vol. 950 (Springer, Heidelberg, 1995), pp. 275\u2013286","DOI":"10.1007\/BFb0053443"},{"key":"9438_CR13","doi-asserted-by":"crossref","unstructured":"D. Cash, E. Kiltz, V. Shoup, The twin Diffie-Hellman problem and applications, in Smart, N.P. (ed.) EUROCRYPT\u00a02008. LNCS, vol. 4965 (Springer, Heidelberg, 2008), pp. 127\u2013145","DOI":"10.1007\/978-3-540-78967-3_8"},{"key":"9438_CR14","doi-asserted-by":"crossref","unstructured":"K. Cohn-Gordon, C. Cremers, K. Gj\u00f8steen, H. Jacobsen, T. Jager, Highly efficient key exchange protocols with optimal tightness, in Boldyreva, A., Micciancio, D. (eds.) CRYPTO\u00a02019, Part\u00a0III. LNCS, vol. 11694 (Springer, Heidelberg, 2019), pp. 767\u2013797","DOI":"10.1007\/978-3-030-26954-8_25"},{"key":"9438_CR15","doi-asserted-by":"crossref","unstructured":"H. Davis, F. G\u00fcnther, Tighter proofs for the SIGMA and TLS 1.3 key exchange protocols, in Sako, K., Tippenhauer, N.O. (eds.) ACNS 21, Part\u00a0II. LNCS, vol. 12727 (Springer, Heidelberg, 2021), pp. 448\u2013479","DOI":"10.1007\/978-3-030-78375-4_18"},{"key":"9438_CR16","doi-asserted-by":"crossref","unstructured":"C. de Saint Guilhem, M. Fischlin, B. Warinschi, Authentication in key-exchange: Definitions, relations and composition, in: Jia, L., K\u00fcsters, R. (eds.) CSF 2020 Computer Security Foundations Symposium (IEEE Computer Society Press, 2020), pp. 288\u2013303","DOI":"10.1109\/CSF49147.2020.00028"},{"key":"9438_CR17","doi-asserted-by":"crossref","unstructured":"D. Diemert, K. Gellert, T. Jager, L. Lyu, More efficient digital signatures with tight multi-user security, in Garay, J. (ed.) PKC\u00a02021, Part\u00a0II. LNCS, vol. 12711 (Springer, Heidelberg, 2021), pp. 1\u201331","DOI":"10.1007\/978-3-030-75248-4_1"},{"key":"9438_CR18","doi-asserted-by":"crossref","unstructured":"D. Diemert, T. Jager, On the tight security of TLS 1.3: Theoretically sound cryptographic parameters for real-world deployments, J. Cryptol. 34(3), 30 (2021)","DOI":"10.1007\/s00145-021-09388-x"},{"key":"9438_CR19","doi-asserted-by":"crossref","unstructured":"W. Diffie, M.E. Hellman, New directions in cryptography, IEEE Trans. Inf. Theory 22(6), 644\u2013654 (1976)","DOI":"10.1109\/TIT.1976.1055638"},{"key":"9438_CR20","doi-asserted-by":"crossref","unstructured":"W. Diffie, P.C. van Oorschot, M.J. Wiener, Authentication and authenticated key exchanges, Designs Codes Cryptography 2(2), 107\u2013125 (1992)","DOI":"10.1007\/BF00124891"},{"key":"9438_CR21","doi-asserted-by":"crossref","unstructured":"M. Fischlin, F. G\u00fcnther, B. Schmidt, B. Warinschi, Key confirmation in key exchange: A formal treatment and implications for TLS 1.3, in 2016 IEEE Symposium on Security and Privacy (IEEE Computer Society Press, 2016), pp. 452\u2013469","DOI":"10.1109\/SP.2016.34"},{"key":"9438_CR22","doi-asserted-by":"crossref","unstructured":"N. Fleischhacker, T. Jager, D. Schr\u00f6der, On tight security proofs for Schnorr signatures, in P. Sarkar, T. Iwata (eds.) ASIACRYPT\u00a02014, Part\u00a0I. LNCS, vol. 8873 (Springer, Heidelberg, 2014), pp. 512\u2013531","DOI":"10.1007\/978-3-662-45611-8_27"},{"key":"9438_CR23","doi-asserted-by":"publisher","unstructured":"S.D. Galbraith, J. Malone-Lee, N.P. Smart, Public key signatures in the multi-user setting, Inf. Process. Lett. 83(5), 263\u2013266 (2002). https:\/\/doi.org\/10.1016\/S0020-0190(01)00338-6","DOI":"10.1016\/S0020-0190(01)00338-6"},{"key":"9438_CR24","doi-asserted-by":"crossref","unstructured":"K. Gj\u00f8steen, T. Jager, Practical and tightly-secure digital signatures and authenticated key exchange, in Shacham, H., Boldyreva, A. (eds.) CRYPTO\u00a02018, Part\u00a0II. LNCS, vol. 10992 (Springer, Heidelberg, 2018), pp. 95\u2013125","DOI":"10.1007\/978-3-319-96881-0_4"},{"key":"9438_CR25","doi-asserted-by":"crossref","unstructured":"M.C. Gorantla, C. Boyd, J.M. Gonz\u00e1lez Nieto, Modeling key compromise impersonation attacks on group key exchange protocols, in Jarecki, S., Tsudik, G. (eds.) PKC\u00a02009. LNCS, vol. 5443 (Springer, Heidelberg, 2009), pp. 105\u2013123","DOI":"10.1007\/978-3-642-00468-1_7"},{"key":"9438_CR26","doi-asserted-by":"crossref","unstructured":"D. Harkins, D. Carrel, The internet key exchange (IKE). RFC 2409 (1998). https:\/\/www.ietf.org\/rfc\/rfc2409.txt","DOI":"10.17487\/rfc2409"},{"key":"9438_CR27","doi-asserted-by":"crossref","unstructured":"D. Hofheinz, E. Kiltz, The group of signed quadratic residues and applications, in Halevi, S. (ed.) CRYPTO\u00a02009. LNCS, vol. 5677 (Springer, Heidelberg, 2009), pp. 637\u2013653","DOI":"10.1007\/978-3-642-03356-8_37"},{"key":"9438_CR28","doi-asserted-by":"crossref","unstructured":"T. Jager, E. Kiltz, D. Riepel, S. Sch\u00e4ge, Tightly-Secure Authenticated Key Exchange, Revisited. In: Eurocrypt 2021 (2021). https:\/\/ia.cr\/2020\/1279","DOI":"10.1007\/978-3-030-77870-5_5"},{"key":"9438_CR29","doi-asserted-by":"crossref","unstructured":"T. Jager, F. Kohlar, S. Sch\u00e4ge, J. Schwenk, On the security of TLS-DHE in the standard model, in Safavi-Naini, R., Canetti, R. (eds.) CRYPTO\u00a02012. LNCS, vol. 7417 (Springer, Heidelberg, 2012), pp. 273\u2013293","DOI":"10.1007\/978-3-642-32009-5_17"},{"key":"9438_CR30","doi-asserted-by":"crossref","unstructured":"T. Jager, F. Kohlar, S. Sch\u00e4ge, J. Schwenk, Authenticated confidential channel establishment and the security of TLS-DHE, J. Cryptol. 30(4), 1276\u20131324 (2017)","DOI":"10.1007\/s00145-016-9248-2"},{"key":"9438_CR31","doi-asserted-by":"crossref","unstructured":"J. Katz, M. Yung, Scalable protocols for authenticated group key exchange, in Boneh, D. (ed.) CRYPTO\u00a02003. LNCS, vol. 2729 (Springer, Heidelberg, 2003), pp. 110\u2013125","DOI":"10.1007\/978-3-540-45146-4_7"},{"key":"9438_CR32","doi-asserted-by":"crossref","unstructured":"E. Kiltz, D. Masny, J. Pan, Optimal security proofs for signatures from identification schemes, in Robshaw, M., Katz, J. (eds.) CRYPTO\u00a02016, Part\u00a0II. LNCS, vol. 9815 (Springer, Heidelberg, 2016), pp. 33\u201361","DOI":"10.1007\/978-3-662-53008-5_2"},{"key":"9438_CR33","doi-asserted-by":"crossref","unstructured":"H. Krawczyk, SIGMA: The \u201cSIGn-and-MAc\u201d approach to authenticated Diffie-Hellman and its use in the IKE protocols, in Boneh, D. (ed.) CRYPTO\u00a02003. LNCS, vol. 2729 (Springer, Heidelberg, 2003), pp. 400\u2013425","DOI":"10.1007\/978-3-540-45146-4_24"},{"key":"9438_CR34","doi-asserted-by":"crossref","unstructured":"B.A. LaMacchia, K. Lauter, A. Mityagin, Stronger security of authenticated key exchange, in Susilo, W., Liu, J.K., Mu, Y. (eds.) ProvSec 2007. LNCS, vol. 4784 (Springer, Heidelberg, 2007), pp. 1\u201316","DOI":"10.1007\/978-3-540-75670-5_1"},{"key":"9438_CR35","doi-asserted-by":"crossref","unstructured":"Y. Li, S. Sch\u00e4ge, No-match attacks and robust partnering definitions: Defining trivial attacks for security protocols is not trivial, in Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017 (ACM Press, 2017), pp. 1343\u20131360","DOI":"10.1145\/3133956.3134006"},{"key":"9438_CR36","doi-asserted-by":"crossref","unstructured":"X. Liu, S. Liu, D. Gu, J. Weng, Two-pass authenticated key exchange with explicit authentication and tight security, in Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492 (Springer, Heidelberg, 2020), pp. 785\u2013814","DOI":"10.1007\/978-3-030-64834-3_27"},{"key":"9438_CR37","doi-asserted-by":"crossref","unstructured":"U.M. Maurer, Abstract models of computation in cryptography (invited paper), in Smart, N.P. (ed.) 10th IMA International Conference on Cryptography and Coding. LNCS, vol. 3796 (Springer, Heidelberg, 2005), pp. 1\u201312","DOI":"10.1007\/11586821_1"},{"key":"9438_CR38","doi-asserted-by":"crossref","unstructured":"J. Pan, C. Qian, M. Ringerud, Signed diffie-hellman key exchange with tight security, in Paterson, K.G. (ed.) CT-RSA\u00a02021. LNCS, vol. 12704 (Springer, Heidelberg, 2021), pp. 201\u2013226","DOI":"10.1007\/978-3-030-75539-3_9"},{"key":"9438_CR39","doi-asserted-by":"crossref","unstructured":"J. Pan, M. Ringerud, Signatures with tight multi-user security from search assumptions, in L. Chen, N. Li, K. Liang, S.A. Schneider (eds.) ESORICS\u00a02020, Part\u00a0II. LNCS, vol. 12309 (Springer, Heidelberg, 2020), pp. 485\u2013504","DOI":"10.1007\/978-3-030-59013-0_24"},{"key":"9438_CR40","unstructured":"PKCS #1: RSA cryptography standard. RSA Data Security, Inc. (1991)"},{"key":"9438_CR41","doi-asserted-by":"crossref","unstructured":"B. Poettering, P. R\u00f6sler, J. Schwenk, D. Stebila, SoK: Game-based security models for group key exchange, in Paterson, K.G. (ed.) CT-RSA\u00a02021. LNCS, vol. 12704 (Springer, Heidelberg, 2021), pp. 148\u2013176","DOI":"10.1007\/978-3-030-75539-3_7"},{"key":"9438_CR42","doi-asserted-by":"crossref","unstructured":"E. Rescorla, The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446 (Proposed Standard (2018). https:\/\/tools.ietf.org\/html\/rfc8446","DOI":"10.17487\/RFC8446"},{"key":"9438_CR43","doi-asserted-by":"crossref","unstructured":"P. R\u00f6sler, C. Mainka, J. Schwenk, More is less: On the end-to-end security of group chats in signal, whatsapp, and threema, in 2018 IEEE European Symposium on Security and Privacy (EuroS P), pp. 415\u2013429 (2018)","DOI":"10.1109\/EuroSP.2018.00036"},{"key":"9438_CR44","doi-asserted-by":"crossref","unstructured":"C.P. Schnorr, Efficient signature generation by smart cards J. Cryptol. 4(3), 161\u2013174 (1991)","DOI":"10.1007\/BF00196725"},{"key":"9438_CR45","doi-asserted-by":"crossref","unstructured":"V. Shoup, Lower bounds for discrete logarithms and related problems, in Fumy, W. (ed.) EUROCRYPT\u201997. LNCS, vol. 1233 (Springer, Heidelberg, 1997), pp. 256\u2013266","DOI":"10.1007\/3-540-69053-0_18"},{"key":"9438_CR46","doi-asserted-by":"crossref","unstructured":"Y. Xiao, R. Zhang, H. Ma, Tightly secure two-pass authenticated key exchange protocol in the CK model, in Jarecki, S. (ed.) CT-RSA\u00a02020. LNCS, vol. 12006 (Springer, Heidelberg, 2020), pp. 171\u2013198","DOI":"10.1007\/978-3-030-40186-3_9"}],"container-title":["Journal of Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09438-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00145-022-09438-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00145-022-09438-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,20]],"date-time":"2022-10-20T20:11:31Z","timestamp":1666296691000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00145-022-09438-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,9,27]]},"references-count":46,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2022,10]]}},"alternative-id":["9438"],"URL":"https:\/\/doi.org\/10.1007\/s00145-022-09438-y","relation":{},"ISSN":["0933-2790","1432-1378"],"issn-type":[{"value":"0933-2790","type":"print"},{"value":"1432-1378","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,9,27]]},"assertion":[{"value":"4 November 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 August 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 August 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 September 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"26"}}