计算机科学 ›› 2026, Vol. 53 ›› Issue (6): 437-445.doi: 10.11896/jsjkx.250400029
张青, 冯雁, 赵洪, 谢四江, 冯艺萌
ZHANG Qing, FENG Yan, ZHAO Hong, XIE Sijiang, FENG Yimeng
摘要: 认证密钥协商协议作为保障通信实体身份真实性与会话密钥机密性的重要机制,在现代通信系统中发挥着至关重要的作用。然而,目前的认证协议大多依赖于离散对数或整数分解等传统数学难题,不能抵抗量子计算攻击。为应对这一挑战,提出了一种基于格的无证书匿名认证密钥协商协议,其安全性可归约到环上带误差学习问题的难解性。该协议能够在两轮消息交互过程中实现双向认证,同时保证用户匿名性和前向安全性。此外,该协议不需要管理复杂证书,消除了密钥生成中心中存在的密钥托管安全风险。通过形式化和非形式化的安全分析,证明了该协议能够有效抵御多种攻击,具有良好的鲁棒性。对比实验结果表明,该协议在显著提升安全性的同时,有效降低了计算开销。
中图分类号:
| [1]WANG K,DONG J,XIAO F,et al.Research Review on Authenticated Key Agreement Protocols for Internet of Things[J].Journal of Network Space Security Science,2024,2(5):2-16. [2]KHAN M A,ULLAH I,KUMAR N,et al.An efficient and secure certificate-based access control and key agreement scheme for flying ad-hoc networks[J].IEEE Transactions on Vehicular Technology,2021,70(5):4839-4851. [3]HUANG Y,WANG Y,CHEN W,et al.PKI cross-domain authentication model based on alliance chain[J].Computer Engineering and Design,2021,42(11):3043-3051. [4]LIAN H,KANG B,YANG L.Strongly secure identity-based authenticated key agreement protocol with identity concealment for secure communication in 5G network[J].IEEE Access,2024,12:98611-98622. [5]TIAN J,WANG Y,SHEN Y.An identity-based authentication scheme with full anonymity and unlinkability for mobile edge computing[J].IEEE Internet of Things Journal,2024,11(13):23561-23576. [6]SONG J,ZHUANG Y,PAN J,et al.Certificateless secure upload for drive-thru internet[C]//2011 IEEE International Conference on Communications(ICC).2011:1-6. [7]DANIEL R M,RAJSINGH E B,SILAS S.An efficient eCK secure certificateless authenticated key agreement scheme with security against public key replacement attacks[J].Journal of Information Security and Applications,2019,47:156-172. [8]WANG W,HUANG H,XIAO F,et al.Computation-transferable authenticated key agreement protocol for smart healthcare[J].Journal of Systems Architecture,2021,118:102215. [9]LIU X,WANG L,HUAN L,et al.Certificateless anonymousauthentication scheme for internet of vehicles[J].Journal of Electronics and Information,2022,44(1):295-304. [10]ZHOU Y,XU R,QIAO Z,et al.An anonymous and efficientmultimessage and multireceiver certificateless signcryption scheme for VANET[J].IEEE Internet of Things Journal,2023,10(24):22823-22835. [11]WEI G,QIN Y,KOU G,et al.Lightweight certificate-less anony-mous authentication key negotiation scheme in the 5G internet of vehicles[J].Electronics,2024,13(16):3288. [12]DAI Y,ZHOU F,XUE D.Certificateless authentication key exchange protocol for internet of vehicles[J].Journal of Chinese Computer Systems,2024,45(10):2508-2513. [13]DING J,ALSAYIGH S,LANCRENON J,et al.Provably secure password authenticated key exchange based on RLWE for the post-quantum world[C]//Cryptographers' Track at the RSA conference.2017:183-204. [14]ISLAM S H.Provably secure two-party authenticated keyagreement protocol for post-quantum environments[J].Journal of Information Security and Applications,2020,52:102468. [15]WANG J,CHEN T,LIU Y,et al.Efficient two-party authentication key agreement protocol using reconciliation mechanism from lattice[C]//International Conference on Security and Privacy in New Computing Environments.2023:32-47. [16]ZHAO Z,LIAN H,SHEN J.Lattice-based identity-based au-thenticated key exchange protocol [J].Journal of Cryptography,2024,11(2):441-454. [17]DABRA V,BALA A,KUMARI S.LBA-PAKE:Lattice-based anonymous password authenticated key exchange for mobile devices[J].IEEE Systems Journal,2021,15(4):5067-5077. [18]DING R,CHENG C,QIN Y.Further analysis and improve-ments of a lattice-based anonymous PAKE scheme[J].IEEE Systems Journal,2022,16(3):5035-5043. [19]DHARMINDER D,REDDY C B,DAS A K,et al.Post-quantum lattice-Based secure reconciliation enabled key agreement protocol for IoT[J].IEEE Internet of Things Journal,2023,10(3):2680-2692. [20]WEI G,FAN K,ZHANG K,et al.Quantum-safe lattice-based certificateless anonymous authenticated key agreement for internet of things[J].IEEE Internet of Things Journal,2024,11(5):9213-9225. [21]LYUBASHEVSKY V,PEIKERT C,REGEV O.On ideal lattices and learning with errors over rings[J].Journal of the ACM,2013,60(6):1-35. [22]ZHANG J,ZHANG Z,DING J,et al.Authenticated keyexchange from ideal lattices[C]//Advances in Cryptology-EUROCRYPT 2015:34th Annual International Conference on the Theory and Applications of Cryptographic Techniques.2015:719-751. [23]JIANG M,GAO J,PEI T.Efficient and Revocable Ciphertext-Policy Attribute-Based Encryption Scheme on Lattices [J].Systems Engineering and Electronics,2025,47(4):1364-1373. [24]YANG X Y,WU L Q,ZHANG M Q,et al.An efficient CCA-secure cryptosystem over ideal lattices from identity-based encryption[J].Computers & Mathematics with Applications,2013,65(9):1254-1263. [25]DING J,FLUHRER S,RV S.Complete attack on RLWE key exchange with reused keys,without signal leakage[C]//Information Security and Privacy:23rd Australasian Conference.2018:467-486. [26]DING J,XIE X,LIN X.A simple provably secure key exchange scheme based on the learning with errors problem[EB/OL].https://eprint.iacr.org/2012/688.pdf. [27]YANG Y,SUN J,LIU Z,et al.Practical revocable and multi-authority CP-ABE scheme from RLWE for cloud computing[J].Journal of Information Security and Applications,2022,65:103108. [28]KUDLA C,PATERSON K G.Modular security proofs for key agreement protocols[C]//International Conference on the Theoryand Application of Cryptology and Information Security.2005:549-565. [29]DOLEV D,YAO A.On the security of public key protocols[J].IEEE Transactions on Information Theory,1983,29(2):198-208. [30]HUANG Y,XU G,SONG X,et al.An Efficient RLWE-Based Privacy-Preserving Authentication Scheme Based on Edge Computing in Industrial Internet of Things[J].IEEE Transactions on Services Computing,2024,17(5):2012-2026. [31]PURSHARTHI K,MISHRA D.Towards post-quantum au-thenticated key agreement scheme for mobile devices[J].Journal of Information Security and Applications,2024,82:103754. [32]RANA S,MISHRA D.Lattice-based key agreement protocolunder ring-LWE problem for IoT-enabled smart devices[J].Sādhanā,2021,46(2):84. |
|
||