RFC 5683 · INFORMATIONAL · 2010

Password-Authenticated Key Diffie-Hellman Exchange

Overview

RFC 5683, “Password-Authenticated Key Diffie-Hellman Exchange”, is an Informational document published in February 2010 by A. Brusilovsky, I. Faynberg, Z. Zeltsan, S. Patel. The canonical text is published by the RFC Editor.

Abstract

This document proposes to add mutual authentication, based on a human-memorizable password, to the basic, unauthenticated Diffie-Hellman key exchange. The proposed algorithm is called the Password-Authenticated Key (PAK) exchange. PAK allows two parties to authenticate themselves while performing the Diffie-Hellman exchange.

The protocol is secure against all passive and active attacks. In particular, it does not allow either type of attacker to obtain any information that would enable an offline dictionary attack on the password. PAK provides Forward Secrecy. This document is not an Internet Standards Track specification; it is published for informational purposes.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 5683 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2010

Who Is Online

In total there are 42 users online: 0 registered, 38 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Majestic Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354