首页> 外文会议>Cryptographers Track at the RSA Conference >Provably Secure Password Authenticated Key Exchange Based on RLWE for the Post-Quantum World
【24h】

Provably Secure Password Authenticated Key Exchange Based on RLWE for the Post-Quantum World

机译:基于RLWE的RLWE获取Quantumum World的证明安全密码认证密钥交换

获取原文

摘要

Authenticated Key Exchange (AKE) is a cryptographic scheme with the aim to establish a high-entropy and secret session key over a insecure communications network. Password-Authenticated Key Exchange (PAKE) assumes that the parties in play share a simple password, which is cheap and human-memorable and is used to achieve the authentication. PAKEs are practically relevant as these features are extremely appealing in an age where most people access sensitive personal data remotely from more-and-more pervasive hand-held devices. Theoretically, PAKEs allow the secure computation and authentication of a high-entropy piece of data using a low-entropy string as a starting point. In this paper, we apply the recently proposed technique introduced in [19] to construct two lattice-based PAKE protocols enjoying a very simple and elegant design that is an parallel extension of the class of Random Oracle Model (ROM)-based protocols PAK and PPK [13,41], but in the lattice-based setting. The new protocol resembling PAK is three-pass, and provides mutual explicit authentication, while the protocol following the structure of PPK is two-pass, and provides implicit authentication. Our protocols rely on the Ring-Learning-with-Errors (RLWE) assumption, and exploit the additive structure of the underlying ring. They have a comparable level of efficiency to PAK and PPK, which makes them highly attractive. We present a preliminary implementation of our protocols to demonstrate that they are both efficient and practical. We believe they are suitable quantum safe replacements for PAK and PPK.
机译:经过身份验证的密钥交换(AKE)是一种加密方案,其目的是通过不安全的通信网络建立高熵和秘密会话键。密码验证密钥交换(PANGE)假定播放中的各方共享一个简单的密码,这是便宜和人性难忘的,用于实现认证。在大多数人远程从更多更普遍的手持设备远程访问敏感的个人数据的年龄,这些功能实际上是相关的。从理论上讲,p p允许使用低熵字符串作为起点的高熵数据的安全计算和认证。在本文中,我们应用了[19]中介绍的最近提出的技术,构建了两个基于格子的普及协议,享有非常简单而优雅的设计,这是随机Oracle模型(ROM)的类别的协议PAK的平行扩展PPK [13,41],但在基于格子的环境中。类似PAK的新协议是三次通过,提供相互明确的认证,而PPK结构之后的协议是双通,并提供隐式身份验证。我们的协议依赖于环路学习 - 错误(RLWE)假设,并利用底层环的附加结构。它们对PAK和PPK具有相当的效率,这使得它们非常有吸引力。我们提出了初步实施我们的协议,以证明它们既有效又实用。我们认为它们是PAK和PPK的合适量子安全替代品。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号