sHMQV: An Efficient Key Exchange Protocol for Power-Limited Devices

sHMQV: An Efficient Key Exchange Protocol for Power-Limited Devices
复制标题

DOI:
10.1007/978-3-319-17533-1_11
复制
发表时间:
2015-05
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Shijun Zhao;Qianying Zhang
Shijun Zhao;Qianying Zhang
中科院分区:
其他
文献类型:
--
作者:
Shijun Zhao;Qianying Zhang

文献摘要

被引文献

相似文献

在本文中,我们专注于为实际场景设计认证密钥交换协议,其中一方由强大但不可信的主机组成(例如,PC、移动的电话等)和功率受限但可信的设备(例如,可信平台模块、移动的可信模块、智能卡等)。HMQV协议和(s,r)OAKE协议是安全性和效率相结合的最新协议。然而,我们发现它们并不适用于上述场景,因为所有(或部分)在线求幂计算必须在功率受限的可信设备中执行,这使得它们在实际部署中效率低下。为了克服上述效率低下的问题,我们提出了一种HMQV协议的变体,表示为sHMQV,根据一些新的设计原理,具有以下优点:1)消除了临时公钥的验证,其花费一次取幂; 2)功率受限的可信设备仅执行一次取幂,其可以离线预先计算; 3)所有在线取幂计算可以在强大的主机中执行。上述优点使sHMQV享有比HMQV和(s,r)OAKE更好的性能,特别是在本文考虑的场景中部署时。最后在CK模型下正式证明了sHMQV的安全性。
In this paper we focus on designing authenticated key exchange protocols for practical scenarios where the party consists of a powerful but untrusted host (e.g., PC, mobile phone, etc) and a power-limited but trusted device (e.g., Trusted Platform Module, Mobile Trusted Module, Smart Card, etc). HMQV and (s,r)OAKE protocols are the state-of-the-art in the integrity of security and efficiency. However, we find that they are not suitable for the above scenarios as all (or part) of the online exponentiation computations must be performed in the power-limited trusted devices, which makes them inefficient for the deployment in practice.To overcome the above inefficiency, we propose a variant of HMQV protocol, denoted sHMQV, under some new design rationales which bring the following advantages: 1) eliminating the validation of the ephemeral public keys, which costs one exponentiation; 2) the power-limited trusted device only performs one exponentiation, which can be pre-computed offline; 3) all the online exponentiation computations can be performed in the powerful host. The above advantages make sHMQV enjoy better performance than HMQV and (s,r)OAKE, especially when deployed in the scenarios considered in this paper. We finally formally prove the security of sHMQV in the CK model.