RFC 9807: The OPAQUE Augmented Password-Authenticated Key Exchange (aPAKE) Protocol
Recent RFCs 2025-07-24
Summary:
This document describes the OPAQUE protocol, an Augmented (or
Asymmetric) Password-Authenticated Key Exchange (aPAKE) protocol that
supports mutual authentication in a client-server setting without
reliance on PKI and with security against pre-computation attacks
upon server compromise. In addition, the protocol provides forward
secrecy and the ability to hide the password from the server, even
during password registration. This document specifies the core OPAQUE
protocol and one instantiation based on 3DH. This document is a
product of the Crypto Forum Research Group (CFRG) in the IRTF.