Quantum-safe multi-server password-based authenticated key exchange protocol

被引:0
|
作者
Chen, Lin [1 ]
Qu, Tongzhou [1 ]
Yin, Anqi [1 ]
机构
[1] Informat Engn Univ, Inst Elect Technol, Shangcheng East Rd, Zhengzhou 450004, Peoples R China
关键词
Password-authenticated key exchange; Smooth projective hash function; Multi-server; Quantum-safe; EFFICIENT; SECURE; FRAMEWORK;
D O I
10.1007/s11042-023-17984-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Password-based authentication is one of the most prevailing access control mechanism. Typical password-authenticated key exchange (PAKE) protocols are single-server settings and are therefore vulnerable to server compromise attack. To defend against such attack, multi-server PAKE schemes have been advanced, but most of which are built on non-quantum-secure hardness assumptions. Lattice-based cryptosystems are regarded as the most promising one for post-quantum eara by NIST, while the known multi-server password-based authentication solution over lattices achieves merely key transport and is public key infrastructure (PKI)-based, resulting in low efficiency and poor deployability. In this work, we resort to distributed smooth projective hash function (SPHF) to bridge the gap between multi-server PAKE protocol and quantum-security. We first design an exact SPHF and derive the first distributed SPHF over lattices by leveraging the additive homomorphic property of the strong learning with errors (LWE) problem. In particular, the relevant parameters of the public key encryption (PKE) scheme it predicates on are identified, thus eliminating the influence of incomplete lattice homomorphism on the correctness of our SPHFs. Pertinent lattice-based multi-server PAKE protocols are further proposed on both transparent and non-transparent transmission modes by integrating our distributed SPHF into the multi-server framework of Raimondo and Gennaro (EUROCRYPT'03). Our PAKE constructions are able to resist both quantum and sever compromise attacks as well as avoid the expensive cryptographic primitives, including non-interactive zero knowledge (NIZK) proofs, signature/verification, secret sharing and fully homomorphic encryption. Experimental results demonstrate that our SPHFs and PAKE protocols offer better efficiency.
引用
收藏
页码:65011 / 65038
页数:28
相关论文
共 50 条
  • [21] Cryptanalysis of Server-Aided Password-Based Authenticated Key Exchange Protocols
    Nam, Junghyun
    Choo, Kim-Kwang Raymond
    Paik, Juryon
    Won, Dongho
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (02): : 47 - 57
  • [22] A framework for password-based authenticated key exchange
    Gennaro, R
    Lindell, Y
    ADVANCES IN CRYPTOLOGY-EUROCRYPT 2003, 2003, 2656 : 524 - 543
  • [23] Anonymous password-based authenticated key exchange
    Viet, DQ
    Yamamura, A
    Tanaka, H
    PROGRESS IN CRYPTOLOGY - INDOCRYPT 2005, PROCEEDINGS, 2005, 3797 : 244 - 257
  • [24] Cryptanalysis of server-aided password-based authenticated key exchange protocols
    Won, D. (dhwon@security.re.kr), 1600, Science and Engineering Research Support Society, 20 Virginia Court, Sandy Bay, Tasmania, Australia (07):
  • [25] Password-Based Authenticated Key Exchange from Lattices for Client/Server Model
    Jheng, Yi-Siou
    Tso, Raylin
    Chen, Chien-Ming
    Wu, Mu-En
    ADVANCES IN COMPUTER SCIENCE AND UBIQUITOUS COMPUTING, 2018, 474 : 315 - 319
  • [26] Efficient three-party password-based authenticated key exchange protocol
    Xu, C.-X., 1600, Univ. of Electronic Science and Technology of China (41):
  • [27] IPAKE: Isomorphisms for password-based authenticated key exchange
    Catalano, D
    Pointcheval, D
    Pornin, T
    ADVANCES IN CRYPTOLOGY - CRYPTO 2004, PROCEEDINGS, 2004, 3152 : 477 - 493
  • [28] A Simple Password-based Authenticated Key Agreement Protocol
    Lee, Yung-Cheng
    OPTICAL, ELECTRONIC MATERIALS AND APPLICATIONS, PTS 1-2, 2011, 216 : 510 - 513
  • [29] Enhancements of a Three-Party Password-Based Authenticated Key Exchange Protocol
    Wu, Shuhua
    Chen, Kefei
    Zhu, Yuefei
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2013, 10 (03) : 215 - 221
  • [30] Partitioned group password-based authenticated key exchange
    Vasco, María Isabel González (mariaisabel.vasco@urjc.es), 1912, Oxford University Press (60):