<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.irtf-cfrg-augpake" target="https://datatracker.ietf.org/doc/html/draft-irtf-cfrg-augpake-09">
   <front>
      <title>Augmented Password-Authenticated Key Exchange (AugPAKE)</title>
      <author initials="S." surname="Shin" fullname="SeongHan Shin">
         <organization>AIST</organization>
      </author>
      <author initials="K." surname="Kobara" fullname="Kazukuni Kobara">
         <organization>AIST</organization>
      </author>
      <date month="January" day="18" year="2018" />
      <abstract>
	 <t>   This document describes a secure and highly-efficient augmented
   password-authenticated key exchange (AugPAKE) protocol where a user
   remembers a low-entropy password and its verifier is registered in
   the intended server.  In general, the user&#x27;s password is chosen from
   a small set of dictionary, making the password susceptible to offline
   dictionary attacks.  The AugPAKE protocol described here is secure
   against passive attacks, active attacks and offline dictionary
   attacks (on the obtained messages with passive/active attacks).
   Also, this protocol provides resistance to server compromise in the
   context that an attacker, who obtained the password verifier from the
   server, must at least perform offline dictionary attacks to gain any
   advantage in impersonating the user.  The AugPAKE protocol is not
   only provably secure in the random oracle model but also the most
   efficient over the previous augmented PAKE protocols (SRP and AMP).

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-irtf-cfrg-augpake-09" />
   
</reference>
