This standard covers specifications of common public-key cryptographic techniques for performingpassword-based authentication and key establishment, supplemental to the techniques described inIEEE Std 1363(TM)-2000 and IEEE Std 1363a(TM)-2004.1 It includes specifications of primitives and schemesdesigned to utilize passwords and other low-grade secrets as a basis for securing electronic transactions,including schemes for password-authenticated key agreement and password-authenticated key retrieval.
Purpose
Ensuring privacy and authenticity in personal electronic transactions is a process that necessarily involveshuman beings. Memorized secrets are an important factor in human authentication. Many commoncryptographic methods for authentication require large, random high-grade secret keys; yet, the secrets thathuman beings can conveniently memorize and reliably reproduce tend to be low-grade secrets. Passwordsare widely used low-grade secrets that are typically not-so-random and relatively small, and introduce risksof brute-force attack when inappropriately used as cryptographic keys.
Abstract
New IEEE Standard - Active.This standard covers specifications of public-key cryptographic techniques for password-based authentication and key establishment, supplemental to the techniques described in IEEE Std 1363-2000 and IEEE Std 1363a-2004. It is intended as a companion standard to IEEE Std 1363-2000 and IEEE Std 1363a-2004. It includes specifications of primitives and schemes designed to utilize passwords and other low-grade secrets as a basis for securing electronic transactions, including schemes for password-authenticated key agreement and password-authenticated key retrieval.