Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2
RFC 6628, “Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2”, is an Experimental document published in June 2012 by S. Shin, K. Kobara. The canonical text is published by the RFC Editor.
Abstract
This document describes an efficient augmented password-only authentication and key exchange (AugPAKE) protocol where a user remembers a low-entropy password and its verifier is registered in the intended server. In general, the user password is chosen from a small set of dictionary words that allows an attacker to perform exhaustive searches (i.e., off-line dictionary attacks). The AugPAKE protocol described here is secure against passive attacks, active attacks, and off-line dictionary attacks (on the obtained messages with passive/active attacks), and also provides resistance to server compromise (in the context of augmented PAKE security). In addition, this document describes how the AugPAKE protocol is integrated into the Internet Key Exchange Protocol version 2 (IKEv2). This document defines an Experimental Protocol for the Internet community.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 6628 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6627 Overview of Pre-Congestion Notification Encoding
- RFC 6629 Considerations on the Application of the Level 3 Multihoming Shim Protocol for IPv6
- RFC 6626 Dynamic Prefix Allocation for Network Mobility for Mobile IPv4
- RFC 6630 EAP Re-authentication Protocol Extensions for Authenticated Anticipatory Keying
- RFC 6625 Wildcards in Multicast VPN Auto-Discovery Routes
- RFC 6631 Password Authenticated Connection Establishment with the Internet Key Exchange Protocol version 2
- RFC 6624 Layer 2 Virtual Private Networks Using BGP for Auto-Discovery and Signaling
- RFC 6632 An Overview of the IETF Network Management Standards