close

Paper 2025/1647

Universally Composable Password-Hardened Encryption

Behzad Abdolmaleki, University of Sheffield
Ruben Baecker, Friedrich-Alexander-Universität Erlangen-Nürnberg
Paul Gerhart, TU Wien
Mike Graf, University of Stuttgart
Mojtaba Khalili, Isfahan University of Technology
Daniel Rausch, University of Stuttgart
Dominique Schröder, TU Wien
Abstract

Password-Hardened Encryption (PHE) protects against offline brute-force attacks by involving an external ratelimiter that enforces rate-limited decryption without learning passwords or keys. Threshold Password-Hardened Encryption (TPHE), introduced by Brost et al. (CCS’20), distributes this trust among multiple ratelimiters. Despite its promise, the security foundations of TPHE remain unclear. We make three contributions: (1) We uncover a flaw in the proof of Brost et al.’s TPHE scheme, which invalidates its claimed security and leaves the guarantees of existing constructions uncertain; (2) We provide the first universal composability (UC) formalization of PHE and TPHE, unifying previous fragmented models and supporting key rotation, an essential feature for long-term security and related primitives such as updatable encryption; (3) We present the first provably secure TPHE scheme, which is both round-optimal and UC-secure, thus composable in real-world settings; and we implement and evaluate our protocol, demonstrating practical efficiency that outperforms prior work in realistic WAN scenarios.

Metadata
Available format(s)
PDF
Category
Cryptographic protocols
Publication info
Published by the IACR in ASIACRYPT 2025
Keywords
Password-Hardened EncryptionThreshold CryptographyUniversal Composability
Contact author(s)
behzad abdolmaleki @ sheffield ac uk
ruben baecker @ fau de
paul gerhart @ tuwien ac at
mike graf @ sec uni-stuttgart de
mojtabakhalyly @ gmail com
daniel rausch @ sec uni-stuttgart de
dominique schroeder @ tuwien ac at
History
2025-09-12: approved
2025-09-11: received
See all versions
Short URL
https://ia.cr/2025/1647
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1647,
      author = {Behzad Abdolmaleki and Ruben Baecker and Paul Gerhart and Mike Graf and Mojtaba Khalili and Daniel Rausch and Dominique Schröder},
      title = {Universally Composable Password-Hardened Encryption},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1647},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1647}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.