[rfc-dist] RFC 5683 on Password-Authenticated Key (PAK) Diffie-Hellman Exchange

rfc-editor at rfc-editor.org rfc-editor at rfc-editor.org
Mon Feb 8 18:55:11 PST 2010

A new Request for Comments is now available in online RFC libraries.

        RFC 5683

        Title:      Password-Authenticated Key (PAK) Diffie-Hellman 
        Author:     A. Brusilovsky, I. Faynberg,
                    Z. Zeltsan, S. Patel
        Status:     Informational
        Date:       February 2010
        Mailbox:    Alec.Brusilovsky at alcatel-lucent.com, 
                    igor.faynberg at alcatel-lucent.com, 
                    zeltsan at alcatel-lucent.com,  sarvar at google.com
        Pages:      10
        Characters: 17820
        Updates/Obsoletes/SeeAlso:   None

        I-D Tag:    draft-brusilovsky-pak-10.txt

        URL:        http://www.rfc-editor.org/rfc/rfc5683.txt

This document proposes to add mutual authentication, based on a
human-memorizable password, to the basic, unauthenticated Diffie-Hellman
key exchange.  The proposed algorithm is called the Password-Authenticated
Key (PAK) exchange.  PAK allows two parties to authenticate themselves
while performing the Diffie-Hellman exchange.

The protocol is secure against all passive and active attacks.
In particular, it does not allow either type of attacker to obtain any
information that would enable an offline dictionary attack on the
password.  PAK provides Forward Secrecy.  This document is not an 
Internet Standards Track specification; it is published for informational 

INFORMATIONAL: This memo provides information for the Internet community.
It does not specify an Internet standard of any kind. Distribution of
this memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see

For searching the RFC series, see http://www.rfc-editor.org/rfcsearch.html.
For downloading RFCs, see http://www.rfc-editor.org/rfc.html.

Requests for special distribution should be addressed to either the
author of the RFC in question, or to rfc-editor at rfc-editor.org.  Unless
specifically noted otherwise on the RFC itself, all RFCs are for
unlimited distribution.

The RFC Editor Team
Association Management Solutions, LLC

More information about the rfc-dist mailing list