RFC 9382 · INFORMATIONAL · 2023

SPAKE2, a Password-Authenticated Key Exchange

Overview

RFC 9382, “SPAKE2, a Password-Authenticated Key Exchange”, is an Informational document published in September 2023 by W. Ladd. The canonical text is published by the RFC Editor.

Abstract

This document describes SPAKE2, which is a protocol for two parties that share a password to derive a strong shared key without disclosing the password. This method is compatible with any group, is computationally efficient, and has a security proof. This document predated the Crypto Forum Research Group (CFRG) password-authenticated key exchange (PAKE) competition, and it was not selected; however, given existing use of variants in Kerberos and other applications, it was felt that publication was beneficial. Applications that need a symmetric PAKE, but are unable to hash onto an elliptic curve at execution time, can use SPAKE2. This document is a product of the Crypto Forum Research Group in the Internet Research Task Force (IRTF).

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 9382 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2023

Who Is Online

In total there are 51 users online: 0 registered, 43 guests and 8 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot DuckDuckBot Googlebot Majestic Other Bot Other Crawler SemrushBot Sogou

Users active in the past 15 minutes. Total registered members: 354