Quantum Safe Computation-Friendly Identity-Binding Password Authenticated Key Exchange

Pratima Jana*, Ratna Dutta, Cong Zuo

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Password Authenticated Key Exchange (PAKE) protocols are of paramount importance in applications like the Internet of Things (IoT) and wireless networking ensures the security of communication systems by enabling two parties to establish a shared secret key using only a low-entropy password. Recent advances in PAKE protocols have aimed to provide stronger security assurances including resilience against offline dictionary attacks, replay attacks, compromise attacks for both parties (client and server), pre-computation attacks, mutual authentication and perfect forward secrecy. Despite several improvements, challenges persist in both security and efficiency for existing PAKE proposals. To address these challenges, Cremers et al. (Crypto ’22) introduced the concept of identity-binding PAKE. None of the existing identity-binding PAKE is post-quantum secure. In response to these challenges, our contribution aims to bridge the gap in practical and secure post-quantum identity-binding PAKE. Our work proposes a post-quantum secure identity-binding PAKE protocols, LPAKE with enhanced security. Our lattice-based protocol LPAKE is secure based on the Module Pairing with Errors (MPWE) assumption and the Decision Module Learning with Errors (DMLWE) assumption. We present comprehensive security proof in a conventional game-based indistinguishability security model. Through rigorous performance evaluations, the paper demonstrates that the proposed PAKE scheme exhibits notable advantages in terms of total computation cost with enhanced security properties compared to existing identity-binding PAKE protocols.

Original languageEnglish
Title of host publicationProvable and Practical Security - 18th International Conference, ProvSec 2024, Proceedings
EditorsJoseph K. Liu, Liqun Chen, Shi-Feng Sun, Xiaoning Liu
PublisherSpringer Science and Business Media Deutschland GmbH
Pages298-309
Number of pages12
ISBN (Print)9789819609567
DOIs
Publication statusPublished - 2025
Event18th International Conference on Provable and Practical Security, ProvSec 2024 - Gold Coast, Australia
Duration: 25 Sept 202427 Sept 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14904 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference18th International Conference on Provable and Practical Security, ProvSec 2024
Country/TerritoryAustralia
CityGold Coast
Period25/09/2427/09/24

Keywords

  • Authenticated Key Exchange
  • Internet of Things
  • Lattice-based Cryptography
  • Post-quantum Cryptography

Fingerprint

Dive into the research topics of 'Quantum Safe Computation-Friendly Identity-Binding Password Authenticated Key Exchange'. Together they form a unique fingerprint.

Cite this