RFC 6628 · EXPERIMENTAL · 2012

Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2

Overview

RFC 6628, “Efficient Augmented Password-Only Authentication and Key Exchange for IKEv2”, is an Experimental document published in June 2012 by S. Shin, K. Kobara. The canonical text is published by the RFC Editor.

Abstract

This document describes an efficient augmented password-only authentication and key exchange (AugPAKE) protocol where a user remembers a low-entropy password and its verifier is registered in the intended server. In general, the user password is chosen from a small set of dictionary words that allows an attacker to perform exhaustive searches (i.e., off-line dictionary attacks). The AugPAKE protocol described here is secure against passive attacks, active attacks, and off-line dictionary attacks (on the obtained messages with passive/active attacks), and also provides resistance to server compromise (in the context of augmented PAKE security). In addition, this document describes how the AugPAKE protocol is integrated into the Internet Key Exchange Protocol version 2 (IKEv2). This document defines an Experimental Protocol for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 6628 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2012

Who Is Online

In total there are 266 users online: 0 registered, 256 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler Other Spider PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372