CurrentINFORMATIONALINDEPENDENT stream

RFC 5683: Password-Authenticated Key (PAK) Diffie-Hellman Exchange

In plain English — editorial summary, not part of the RFC

This document proposes to add mutual authentication, based on a human-memorizable password, to the basic, unauthenticated Diffie-Hellman key exchange. The proposed algorithm is called the Password-Authenticated Key (PAK) exchange. PAK allows two parties to authenticate themselves while performing the Diffie-Hellman exchange. The protocol is secure against all passive and active attacks. In particular, it does not allow either type of attacker to obtain any information that would enable an offline dictionary attack on the password. PAK provides Forward Secrecy. This document is not an Internet Standards Track specification; it is published for informational purposes.

Document record

Document ID
RFC5683
Published
February 2010
Authors
A. Brusilovsky; I. Faynberg; Z. Zeltsan; S. Patel
Status
INFORMATIONAL
Stream
INDEPENDENT
Area
Pages
10
Also known as

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/5683-password-authenticated-key-pak-diffie-hellman-exchange