AI & Computingarticle2026-08-03

SoK: PQC PAKEs Design, Security and Performance

Open access0 citations

Abstract

Password Authenticated Key Exchange (PAKE) establishes secure communication channels using passwords for authentication. Currently, standardized PAKEs rely on classical asymmetric cryptography. However, these PAKEs may become insecure should the expected quantum threat become a reality. Despite the growing interest in realizing quantum-safe PAKEs, they did not receive much attention from the ongoing Post-Quantum Cryptography (PQC) integration efforts. Hence, there is a significant awareness gap compared to PQC primitives subject to the official standardization processes. We provide a comprehensive overview of existing PQC PAKEs, classify their design rationales and authentication methods, and address aspects related to their security and performance. We identify PAKE designs that are still unexplored in the PQC realm and discuss the possibility of their adaptation. Thus, we offer a detailed reference for future work on PQC PAKEs.

// Source

View paper (DOI)Open access versionOpenAlexIACR Communications in CryptologyPublished 2026-08-03

Authors: Nouri Alnahawi, David Haas, Erik Mauß, Alexander Wiesmaier

Institutions: Darmstadt University of Applied Sciences, EU Business School, Geneva, SBS CyberSecurity (United States)