格上无非交互式零知识证明的两轮三方PAKE协议  

Two-round three-party password-authenticated key exchange protocol over lattices without non-interactive zero-knowledge proof

在线阅读下载全文

作  者:尹新媛 郑小建[1] 熊金波[1] YIN Xinyuan;ZHENG Xiaojian;XIONG Jinbo(College of Computer and Cyber Security,Fujian Normal University,Fuzhou Fujian 350117,China)

机构地区:[1]福建师范大学计算机与网络空间安全学院,福州350117

出  处:《计算机应用》2024年第3期805-810,共6页journal of Computer Applications

基  金:国家自然科学基金资助项目(62272102)。

摘  要:针对现有基于格的三方口令认证密钥交换(PAKE)协议通信轮次较多、执行效率较低等问题,提出一种格上无非交互式零知识证明的两轮三方PAKE协议。首先,利用非适应性近似平滑投影哈希函数实现密钥交换,在不使用非交互式零知识(NIZK)证明的前提下,降低协议的通信轮数;其次,利用哈希值和投影哈希值构造会话密钥,不需要使用随机预言机,避免了随机预言机导致的潜在口令猜测攻击。在标准模型下给出所提协议的形式化安全证明。仿真结果表明,与基于格的三方PAKE协议相比,所提协议的执行时间在客户端缩短了89.2%~98.6%,在服务器端缩短了19.0%~91.6%。验证了所提协议能够抵抗量子攻击,具有较高的执行效率,同时减少了协议通信轮数。Focused on the issues of high communication rounds and low execution efficiency in existing lattice-based three-party Password-Authenticated Key Exchange(PAKE)protocols,a two-round three-party PAKE protocol over lattices without Non-Interactive Zero-Knowledge(NIZK)proof was proposed.First,the advantage of non-adaptive approximate smooth projective hash function was taken to achieve key exchange and reduce the number of communication rounds without NIZK proof.Second,session keys were constructed by using hash values and projection hash values without random oracles,thus avoiding potential password guessing attacks.Finally,formal security proof of the proposed protocol was given in the standard model.Simulation results show that compared with lattice-based three-party PAKE protocols,the proposed protocol has the execution time reduced by 89.2%-98.6% on the client side and 19.0%-91.6% on the server side.It is verified that the proposed protocol can resist quantum attacks with high execution efficiency and few communication rounds.

关 键 词: 三方密钥交换 口令认证密钥交换 非交互式零知识 可证明安全 

分 类 号:TP309[自动化与计算机技术—计算机系统结构]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象