# On the Provable Security of the Dragonfly Protocol

## Abstract

**Dragonfly** is a password-authenticated key exchange protocol that was proposed by Harkins [11] in 2008. It is currently a candidate for standardization by the Internet Engineering Task Force, and would greatly benefit from a security proof. In this paper, we prove the security of a very close variant of **Dragonfly** in the random oracle model. It shows in particular that **Dragonfly**’s main flows - a kind of Diffie-Hellman variation with a password-derived base - are sound. We employ the standard Bellare et al. [2] security model, which incorporates forward secrecy.

## Notes

### Acknowledgments

We thank the anonymous reviewers for their helpful comments. This work was partially supported by project SEQUOIA, a joint project between the *Fonds National de la Recherche, Luxembourg* and the *Agence Nationale de la Recherche* (France).

