计算机科学 ›› 2026, Vol. 53 ›› Issue (6): 437-445.doi: 10.11896/jsjkx.250400029

• 信息安全 • 上一篇    下一篇

基于格的无证书匿名认证密钥协商协议

张青, 冯雁, 赵洪, 谢四江, 冯艺萌   

  1. 北京电子科技学院网络空间安全系 北京 100070
  • 收稿日期:2025-04-07 修回日期:2025-07-06 出版日期:2026-06-15 发布日期:2026-06-09
  • 通讯作者: 冯雁(fengy@besti.edu.cn)
  • 作者简介:(q_zhang163@163.com)
  • 基金资助:
    国家重点研发计划(2024YFB3108104);中央高校基本科研业务费专项基金(3282024044)

Certificateless Anonymous Authentication Key Agreement Protocol Based on Lattice

ZHANG Qing, FENG Yan, ZHAO Hong, XIE Sijiang, FENG Yimeng   

  1. Cyberspace Security Department,Beijing Electronic Science and Technology Institute,Beijing 100070,China
  • Received:2025-04-07 Revised:2025-07-06 Published:2026-06-15 Online:2026-06-09
  • About author:ZHANG Qing,born in 2001,postgra-duate.Her main research interests include cyberspace security and post quantum cryptography.
    FENG Yan,born in 1979,associate professor.Her main research interests include cryptography,network security,and quantum communication network security system.
  • Supported by:
    National Key Research and Development Program of China(2024YFB3108104) and Fundamental Research Funds for the Central Universities(3282024044).

摘要: 认证密钥协商协议作为保障通信实体身份真实性与会话密钥机密性的重要机制,在现代通信系统中发挥着至关重要的作用。然而,目前的认证协议大多依赖于离散对数或整数分解等传统数学难题,不能抵抗量子计算攻击。为应对这一挑战,提出了一种基于格的无证书匿名认证密钥协商协议,其安全性可归约到环上带误差学习问题的难解性。该协议能够在两轮消息交互过程中实现双向认证,同时保证用户匿名性和前向安全性。此外,该协议不需要管理复杂证书,消除了密钥生成中心中存在的密钥托管安全风险。通过形式化和非形式化的安全分析,证明了该协议能够有效抵御多种攻击,具有良好的鲁棒性。对比实验结果表明,该协议在显著提升安全性的同时,有效降低了计算开销。

关键词: 格密码, 认证密钥协商协议, 环上带误差学习, 无证书, 匿名

Abstract: Authentication key agreement protocols are crucial mechanisms for ensuring the authenticity of communication entities and the confidentiality of session keys,playing a vital role in modern communication systems.However,most current authentication protocols rely on traditional mathematical problems such as discrete logarithm or integer factorization,which are vulnerable to quantum computing attacks.To address this challenge,a certificateless anonymous authentication key agreement protocol based on lattices is proposed,whose security can be reduced to the intractability of the ring learning with errors problem.The proposed protocol achieves mutual authentication within two rounds of message exchanges,while ensuring user anonymity and forward security.Moreover,it eliminates the need for managing complex certificates,thereby mitigating the security risks associated with key management center.Through both formal and informal security analyses,it is demonstrated that the protocol effectively resists various attacks and exhibits strong robustness.Performance comparison results indicate that the protocol significantly enhances security while effectively reducing computational overhead.

Key words: Lattice-based cryptography, Authenticated key agreement protocol, Ring learning with errors, Certificateless, Anonymous

中图分类号: 

  • TP309
[1]WANG K,DONG J,XIAO F,et al.Research Review on Authenticated Key Agreement Protocols for Internet of Things[J].Journal of Network Space Security Science,2024,2(5):2-16.
[2]KHAN M A,ULLAH I,KUMAR N,et al.An efficient and secure certificate-based access control and key agreement scheme for flying ad-hoc networks[J].IEEE Transactions on Vehicular Technology,2021,70(5):4839-4851.
[3]HUANG Y,WANG Y,CHEN W,et al.PKI cross-domain authentication model based on alliance chain[J].Computer Engineering and Design,2021,42(11):3043-3051.
[4]LIAN H,KANG B,YANG L.Strongly secure identity-based authenticated key agreement protocol with identity concealment for secure communication in 5G network[J].IEEE Access,2024,12:98611-98622.
[5]TIAN J,WANG Y,SHEN Y.An identity-based authentication scheme with full anonymity and unlinkability for mobile edge computing[J].IEEE Internet of Things Journal,2024,11(13):23561-23576.
[6]SONG J,ZHUANG Y,PAN J,et al.Certificateless secure upload for drive-thru internet[C]//2011 IEEE International Conference on Communications(ICC).2011:1-6.
[7]DANIEL R M,RAJSINGH E B,SILAS S.An efficient eCK secure certificateless authenticated key agreement scheme with security against public key replacement attacks[J].Journal of Information Security and Applications,2019,47:156-172.
[8]WANG W,HUANG H,XIAO F,et al.Computation-transferable authenticated key agreement protocol for smart healthcare[J].Journal of Systems Architecture,2021,118:102215.
[9]LIU X,WANG L,HUAN L,et al.Certificateless anonymousauthentication scheme for internet of vehicles[J].Journal of Electronics and Information,2022,44(1):295-304.
[10]ZHOU Y,XU R,QIAO Z,et al.An anonymous and efficientmultimessage and multireceiver certificateless signcryption scheme for VANET[J].IEEE Internet of Things Journal,2023,10(24):22823-22835.
[11]WEI G,QIN Y,KOU G,et al.Lightweight certificate-less anony-mous authentication key negotiation scheme in the 5G internet of vehicles[J].Electronics,2024,13(16):3288.
[12]DAI Y,ZHOU F,XUE D.Certificateless authentication key exchange protocol for internet of vehicles[J].Journal of Chinese Computer Systems,2024,45(10):2508-2513.
[13]DING J,ALSAYIGH S,LANCRENON J,et al.Provably secure password authenticated key exchange based on RLWE for the post-quantum world[C]//Cryptographers' Track at the RSA conference.2017:183-204.
[14]ISLAM S H.Provably secure two-party authenticated keyagreement protocol for post-quantum environments[J].Journal of Information Security and Applications,2020,52:102468.
[15]WANG J,CHEN T,LIU Y,et al.Efficient two-party authentication key agreement protocol using reconciliation mechanism from lattice[C]//International Conference on Security and Privacy in New Computing Environments.2023:32-47.
[16]ZHAO Z,LIAN H,SHEN J.Lattice-based identity-based au-thenticated key exchange protocol [J].Journal of Cryptography,2024,11(2):441-454.
[17]DABRA V,BALA A,KUMARI S.LBA-PAKE:Lattice-based anonymous password authenticated key exchange for mobile devices[J].IEEE Systems Journal,2021,15(4):5067-5077.
[18]DING R,CHENG C,QIN Y.Further analysis and improve-ments of a lattice-based anonymous PAKE scheme[J].IEEE Systems Journal,2022,16(3):5035-5043.
[19]DHARMINDER D,REDDY C B,DAS A K,et al.Post-quantum lattice-Based secure reconciliation enabled key agreement protocol for IoT[J].IEEE Internet of Things Journal,2023,10(3):2680-2692.
[20]WEI G,FAN K,ZHANG K,et al.Quantum-safe lattice-based certificateless anonymous authenticated key agreement for internet of things[J].IEEE Internet of Things Journal,2024,11(5):9213-9225.
[21]LYUBASHEVSKY V,PEIKERT C,REGEV O.On ideal lattices and learning with errors over rings[J].Journal of the ACM,2013,60(6):1-35.
[22]ZHANG J,ZHANG Z,DING J,et al.Authenticated keyexchange from ideal lattices[C]//Advances in Cryptology-EUROCRYPT 2015:34th Annual International Conference on the Theory and Applications of Cryptographic Techniques.2015:719-751.
[23]JIANG M,GAO J,PEI T.Efficient and Revocable Ciphertext-Policy Attribute-Based Encryption Scheme on Lattices [J].Systems Engineering and Electronics,2025,47(4):1364-1373.
[24]YANG X Y,WU L Q,ZHANG M Q,et al.An efficient CCA-secure cryptosystem over ideal lattices from identity-based encryption[J].Computers & Mathematics with Applications,2013,65(9):1254-1263.
[25]DING J,FLUHRER S,RV S.Complete attack on RLWE key exchange with reused keys,without signal leakage[C]//Information Security and Privacy:23rd Australasian Conference.2018:467-486.
[26]DING J,XIE X,LIN X.A simple provably secure key exchange scheme based on the learning with errors problem[EB/OL].https://eprint.iacr.org/2012/688.pdf.
[27]YANG Y,SUN J,LIU Z,et al.Practical revocable and multi-authority CP-ABE scheme from RLWE for cloud computing[J].Journal of Information Security and Applications,2022,65:103108.
[28]KUDLA C,PATERSON K G.Modular security proofs for key agreement protocols[C]//International Conference on the Theoryand Application of Cryptology and Information Security.2005:549-565.
[29]DOLEV D,YAO A.On the security of public key protocols[J].IEEE Transactions on Information Theory,1983,29(2):198-208.
[30]HUANG Y,XU G,SONG X,et al.An Efficient RLWE-Based Privacy-Preserving Authentication Scheme Based on Edge Computing in Industrial Internet of Things[J].IEEE Transactions on Services Computing,2024,17(5):2012-2026.
[31]PURSHARTHI K,MISHRA D.Towards post-quantum au-thenticated key agreement scheme for mobile devices[J].Journal of Information Security and Applications,2024,82:103754.
[32]RANA S,MISHRA D.Lattice-based key agreement protocolunder ring-LWE problem for IoT-enabled smart devices[J].Sādhanā,2021,46(2):84.
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!