International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Another look at HMQV

Authors:
Alfred Menezes
Download:
URL: http://eprint.iacr.org/2005/205
Search ePrint
Search Google
Abstract: HMQV is a `hashed variant' of the MQV key agreement protocol. It was recently introduced by Krawczyk, who claimed that HMQV has very significant advantages over MQV: (i) a security proof under reasonable assumptions in the (extended) Canetti-Krawczyk model for key exchange; and (ii) superior performance in some situations. In this paper we demonstrate that HMQV is insecure by presenting realistic attacks in the Canetti-Krawczyk model that recover a victim's static private key. We propose HMQV-1, a patched version of HMQV that resists our attacks (but does not have any performance advantages over MQV). We also identify the fallacies in the security proof for HMQV, critique the security model, and raise some questions about the assurances that proofs in this model can provide.
BibTeX
@misc{eprint-2005-12541,
  title={Another look at HMQV},
  booktitle={IACR Eprint archive},
  keywords={},
  url={http://eprint.iacr.org/2005/205},
  note={ ajmeneze@uwaterloo.ca 13089 received 29 Jun 2005, last revised 2 Nov 2005},
  author={Alfred Menezes},
  year=2005
}