Post-quantum Anonymous One-Sided Authenticated Key Exchange Without Random Oracles

Post-quantum Anonymous One-Sided Authenticated Key Exchange Without Random Oracles
复制标题

DOI:
10.1007/978-3-030-97131-1_2
复制
发表时间:
2022
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Ren Ishibashi;Kazuki Yoneyama
Ren Ishibashi;Kazuki Yoneyama
中科院分区:
其他
文献类型:
--
作者:
Ren Ishibashi;Kazuki Yoneyama

文献摘要

相似文献

认证密钥交换(AKE)是一种在多方之间共享公共会话密钥的加密协议。通常,基于PKI的AKE方案被设计为保证会话密钥的保密性和相互认证。然而,在实践中,有许多情况下,相互认证是不可取的,例如在匿名网络中,如Tor和Riffle,或者由于用户级别的证书管理,如互联网,难以实现。Goldberg等人提出了一种匿名的单边AKE模型,该模型通过只允许客户端对服务器进行认证来保证客户端的匿名性,并给出了具体的方案。然而,现有的匿名单边AKE方案仅在随机预言模型下是安全的。在本文中,我们提出了一般的结构匿名单边AKE在随机预言机模型和标准模型,分别。我们的构造使我们能够构造第一个后量子匿名的单边AKE方案从标准模型中的同源。
Authenticated Key Exchange (AKE) is a cryptographic protocol to share a common session key among multiple parties. Usually, PKI-based AKE schemes are designed to guarantee secrecy of the session key and mutual authentication. However, in practice, there are many cases where mutual authentication is undesirable such as in anonymous networks like Tor and Riffle, or difficult to achieve due to the certificate management at the user level such as the Internet. Goldberg et al. formulated a model of anonymous one-sided AKE which guarantees the anonymity of the client by allowing only the client to authenticate the server, and proposed a concrete scheme. However, existing anonymous one-sided AKE schemes are only known to be secure in the random oracle model. In this paper, we propose generic constructions of anonymous one-sided AKE in the random oracle model and in the standard model, respectively. Our constructions allow us to construct the first post-quantum anonymous one-sided AKE scheme from isogenies in the standard model.