Quantum-safe multi-server password-based authenticated key exchange protocol

被引:0
|
作者
Chen, Lin [1 ]
Qu, Tongzhou [1 ]
Yin, Anqi [1 ]
机构
[1] Informat Engn Univ, Inst Elect Technol, Shangcheng East Rd, Zhengzhou 450004, Peoples R China
关键词
Password-authenticated key exchange; Smooth projective hash function; Multi-server; Quantum-safe; EFFICIENT; SECURE; FRAMEWORK;
D O I
10.1007/s11042-023-17984-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Password-based authentication is one of the most prevailing access control mechanism. Typical password-authenticated key exchange (PAKE) protocols are single-server settings and are therefore vulnerable to server compromise attack. To defend against such attack, multi-server PAKE schemes have been advanced, but most of which are built on non-quantum-secure hardness assumptions. Lattice-based cryptosystems are regarded as the most promising one for post-quantum eara by NIST, while the known multi-server password-based authentication solution over lattices achieves merely key transport and is public key infrastructure (PKI)-based, resulting in low efficiency and poor deployability. In this work, we resort to distributed smooth projective hash function (SPHF) to bridge the gap between multi-server PAKE protocol and quantum-security. We first design an exact SPHF and derive the first distributed SPHF over lattices by leveraging the additive homomorphic property of the strong learning with errors (LWE) problem. In particular, the relevant parameters of the public key encryption (PKE) scheme it predicates on are identified, thus eliminating the influence of incomplete lattice homomorphism on the correctness of our SPHFs. Pertinent lattice-based multi-server PAKE protocols are further proposed on both transparent and non-transparent transmission modes by integrating our distributed SPHF into the multi-server framework of Raimondo and Gennaro (EUROCRYPT'03). Our PAKE constructions are able to resist both quantum and sever compromise attacks as well as avoid the expensive cryptographic primitives, including non-interactive zero knowledge (NIZK) proofs, signature/verification, secret sharing and fully homomorphic encryption. Experimental results demonstrate that our SPHFs and PAKE protocols offer better efficiency.
引用
收藏
页码:65011 / 65038
页数:28
相关论文
共 50 条
  • [1] PASSWORD-BASED AUTHENTICATED KEY EXCHANGE PROTOCOL WITHOUT TRUSTED THIRD PARTY FOR MULTI-SERVER ENVIRONMENTS
    Hsu, Chien-Lung
    Wu, Tzong-Sun
    Lin, Han-Yu
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2012, 8 (3A): : 1541 - 1555
  • [2] Privacy Preserving Password-Based Multi-server Authenticated Key Agreement Protocol Using Smart Card
    Mishra, Dheerendra
    Dhal, Subhasish
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (01) : 1 - 21
  • [3] Privacy Preserving Password-Based Multi-server Authenticated Key Agreement Protocol Using Smart Card
    Dheerendra Mishra
    Subhasish Dhal
    Wireless Personal Communications, 2018, 99 : 1 - 21
  • [4] Practical password-based authenticated key exchange protocol
    Wu, Shuhua
    Zhu, Yuefei
    COMPUTATIONAL INTELLIGENCE AND SECURITY, 2007, 4456 : 523 - 533
  • [5] SSO password-based multi-server authentication protocol
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2012, 9 (1-2) : 161 - 180
  • [6] A Threshold Multi-Server Protocol for Password-Based Authentication
    Guan, Mengxiang
    Song, Jiaxing
    Liu, Weidong
    2016 IEEE 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2016, : 108 - 118
  • [7] Password Authenticated Key Exchange Protocol for Multi-Server Mobile Networks Based on Chebyshev Chaotic Map
    Hsu, Chien-Lung
    Lin, Tzu-Wei
    2013 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS (PERCOM WORKSHOPS), 2013, : 90 - 95
  • [8] Password-Based Authenticated Key Exchange
    Pointcheval, David
    PUBLIC KEY CRYPTOGRAPHY - PKC 2012, 2012, 7293 : 390 - 397
  • [9] Analysis and improvement of a password-based authenticated key exchange protocol
    Shu, Jian
    Xu, Chun-Xiang
    Tongxin Xuebao/Journal on Communications, 2010, 31 (03): : 51 - 56
  • [10] Design of a password-based authenticated key exchange protocol for SIP
    Mishra, Dheerendra
    MULTIMEDIA TOOLS AND APPLICATIONS, 2016, 75 (23) : 16017 - 16038