Authenticated Key Exchange ( \({\textsf {AKE}}\) ) can be used in client-server applications for mutual authentication and key establishment. In scenarios where client authentication is neither feasible nor desirable, One-Sided AKE ( \({\textsf {OS-AKE}}\) ) allows both parties to establish a key while only the server authenticates to the client. Thus, \({\textsf {OS-AKE}}\) provides client anonymity with respect to the server, but does not allow the server to enforce any form of access control—that is, the server simply establishes a key with any client. In this paper, we introduce Anonymous AKE ( \({\textsf {A-AKE}}\) ) to strike a balance between classical client authentication of \({\textsf {AKE}}\) and client anonymity of \({\textsf {OS-AKE}}\) . In a nutshell \({\textsf {A-AKE}}\) is an \({\textsf {AKE}}\) protocol where (i) the server authenticates to the client, (ii) the server can enforce access control by deciding which clients are authorized to run the key-establishment protocol, (iii) a key is established between the server and the client only if the latter is one of the authorized clients as defined by the server, and (iv) the authorized client remains anonymous (within the set of all authorized clients) with respect to the server. We introduce a security model for \({\textsf {A-AKE}}\) that extends popular \({\textsf {AKE}}\) models and design a general framework for instantiating \({\textsf {A-AKE}}\) protocols based on well-established cryptographic primitives. Finally, we instantiate several \({\textsf {AKE}}\) protocols aiming at strong security guarantees in the classical and post-quantum settings. We implement a prototype of each instantiation and provide an experimental comparison of their performance.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Anonymous Authenticated Key Exchange

  • José Ignacio Escribano Pablos,
  • María Isabel González Vasco,
  • Ángel Pérez del Pozo,
  • Claudio Soriente

摘要

Authenticated Key Exchange ( \({\textsf {AKE}}\) ) can be used in client-server applications for mutual authentication and key establishment. In scenarios where client authentication is neither feasible nor desirable, One-Sided AKE ( \({\textsf {OS-AKE}}\) ) allows both parties to establish a key while only the server authenticates to the client. Thus, \({\textsf {OS-AKE}}\) provides client anonymity with respect to the server, but does not allow the server to enforce any form of access control—that is, the server simply establishes a key with any client. In this paper, we introduce Anonymous AKE ( \({\textsf {A-AKE}}\) ) to strike a balance between classical client authentication of \({\textsf {AKE}}\) and client anonymity of \({\textsf {OS-AKE}}\) . In a nutshell \({\textsf {A-AKE}}\) is an \({\textsf {AKE}}\) protocol where (i) the server authenticates to the client, (ii) the server can enforce access control by deciding which clients are authorized to run the key-establishment protocol, (iii) a key is established between the server and the client only if the latter is one of the authorized clients as defined by the server, and (iv) the authorized client remains anonymous (within the set of all authorized clients) with respect to the server. We introduce a security model for \({\textsf {A-AKE}}\) that extends popular \({\textsf {AKE}}\) models and design a general framework for instantiating \({\textsf {A-AKE}}\) protocols based on well-established cryptographic primitives. Finally, we instantiate several \({\textsf {AKE}}\) protocols aiming at strong security guarantees in the classical and post-quantum settings. We implement a prototype of each instantiation and provide an experimental comparison of their performance.